Clarivate · Vulnerability Disclosure
Clarivate Vulnerability Disclosure
Vulnerability disclosure
Clarivate runs a named responsible-disclosure program on HackerOne with a published intake address. What it does NOT do is make any of it machine-discoverable: there is no /.well-known/security.txt on clarivate.com, www.clarivate.com, developer.clarivate.com or any of the three API hosts (see well-known/clarivate-well-known.yml), so an automated scanner finds nothing.
Clarivate runs a coordinated vulnerability disclosure program on Hackerone.
AnalyticsBibliometricsCitationsDataDrug PipelineInsightsIntellectual PropertyLife SciencesPatentsPublicationsResearchScholarly Communication
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.