Clari · Vulnerability Disclosure

Clari Vulnerability Disclosure

Vulnerability disclosure

Clari runs a self-hosted vulnerability disclosure program with a discretionary severity-based reward. It is linked from https://www.clari.com/security/ and is NOT discoverable through /.well-known/security.txt — Clari serves no security.txt on any host (404 on the API hosts, HTTP 200 marketing HTML soft-404 on www.clari.com).

Clari publishes a vulnerability disclosure policy for reporting security issues.

Revenue OperationsForecastingPipeline ManagementSales IntelligenceActivity IntelligenceDeal InsightsCRMConversation IntelligenceB2BEnterpriseMCPAgentsSales EngagementBulk ExportData Ingestion
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.clari.com/vulnerability-disclosure-policy/
name: Clari Vulnerability Disclosure Policy
description: >-
  Clari runs a self-hosted vulnerability disclosure program with a discretionary
  severity-based reward. It is linked from https://www.clari.com/security/ and is NOT
  discoverable through /.well-known/security.txt — Clari serves no security.txt on any
  host (404 on the API hosts, HTTP 200 marketing HTML soft-404 on www.clari.com).
url: https://www.clari.com/vulnerability-disclosure-policy/
http_status: 200
program_type: self-hosted
platform: none
bug_bounty: true
bounty_note: >-
  "Our rewards are based on the severity of a vulnerability." All program parameters
  and payments are "up to the discretion of Clari and may change at any time." Minors
  and sanctioned individuals are ineligible.
reporting:
  channel: web form
  location: form at the bottom of https://www.clari.com/vulnerability-disclosure-policy/
  email: null
  pgp_key: null
  verbatim: "Please submit any potential findings to our program via the form at the bottom of this page."
safe_harbor:
  present: true
  scope: limited
  verbatim: >-
    "Make a good faith effort to avoid privacy violations, destruction of data, and
    interruption or degradation of our service."
  caveat: >-
    Researchers must comply with applicable law and Clari policy; unauthorized access
    and retention of data are prohibited. This is good-faith language rather than a
    full legal safe harbor.
response_commitment:
  sla: none
  verbatim: >-
    Clari will "make every effort to quickly resolve the issue" and remain "responsive"
    with updates during triage and remediation. No timeline is guaranteed.
in_scope_priorities:
- compromise of user data
- account takeover
- remote code execution
- unauthorized access
- authentication bypass
out_of_scope:
- social engineering
- phishing
- denial of service
- missing security best practices (SPF/DKIM/DMARC, CSP)
- unpatched browser issues
- open redirects without a chained impact
related:
- name: Report a Scam
  url: https://www.clari.com/security/report-a-scam/
  note: A separate brand/fraud reporting channel, not a vulnerability channel.
gaps:
- No /.well-known/security.txt on any Clari host, so the policy is invisible to automated discovery (RFC 9116).
- No reporting email or PGP key; the only channel is a web form.
- No published triage or remediation timeline.
x-evidence:
  fetched: '2026-08-13'
  probes:
  - url: https://www.clari.com/vulnerability-disclosure-policy/
    http_status: 200
  - url: https://www.clari.com/security/
    http_status: 200
    finding: 'Links the policy — "To review our guidelines and submit an issue, see our Vulnerability Disclosure Policy"'
  - url: https://www.clari.com/.well-known/security.txt
    http_status: 200
    finding: Marketing HTML shell (soft-404). No security.txt document is served.
  - url: https://api.clari.com/.well-known/security.txt
    http_status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/clari-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.