Clarivate · Vulnerability Disclosure

Clarivate Vulnerability Disclosure

Vulnerability disclosure

Clarivate runs a named responsible-disclosure program on HackerOne with a published intake address. What it does NOT do is make any of it machine-discoverable: there is no /.well-known/security.txt on clarivate.com, www.clarivate.com, developer.clarivate.com or any of the three API hosts (see well-known/clarivate-well-known.yml), so an automated scanner finds nothing.

Clarivate runs a coordinated vulnerability disclosure program on Hackerone.

AnalyticsBibliometricsCitationsDataDrug PipelineInsightsIntellectual PropertyLife SciencesPatentsPublicationsResearchScholarly Communication
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-05'
method: searched
source: >-
  https://clarivate.com/trust-center/ (HTTP 200) and
  the Trust Center disclosure section (the /information-security/responsible-vulnerability-disclosure-program/
  URL now 301s there),
  with the HackerOne program confirmed live at https://hackerone.com/clarivate
  (HTTP 200) on 2026-09-05.
description: >-
  Clarivate runs a named responsible-disclosure program on HackerOne with a published
  intake address. What it does NOT do is make any of it machine-discoverable: there is
  no /.well-known/security.txt on clarivate.com, www.clarivate.com,
  developer.clarivate.com or any of the three API hosts (see
  well-known/clarivate-well-known.yml), so an automated scanner finds nothing.
program:
  exists: true
  type: responsible-disclosure
  platform: HackerOne
  platform_url: https://hackerone.com/clarivate
  platform_status: 200
  policy_url: https://clarivate.com/trust-center/
  policy_url_note: >-
    https://clarivate.com/information-security/responsible-vulnerability-disclosure-program/
    now 301s to https://clarivate.com/trust-center/, where the disclosure statement and
    the hackerone@clarivate.com address are published. Probed 2026-09-05.
  trust_center: https://clarivate.com/trust-center/
  contact_email: hackerone@clarivate.com
  bounty: unknown
  safe_harbor: unstated
  statement: >-
    "We encourage responsible reporting of potential security vulnerabilities in our
    sites and applications. We value the role of external security researchers and
    work collaboratively to verify and address reported issues. If you identify a
    concern report it through our HackerOne Responsible Disclosure Program or email a
    clear description of the issue, its location and steps to reproduce it, to
    hackerone@clarivate.com."
  submission_requirements:
    - A clear description of the issue
    - Its location
    - Steps to reproduce it
security_txt:
  served: false
  probed:
    - url: https://clarivate.com/.well-known/security.txt
      status: 404
    - url: https://www.clarivate.com/.well-known/security.txt
      status: 404
    - url: https://developer.clarivate.com/.well-known/security.txt
      status: 404
    - url: https://api.clarivate.com/.well-known/security.txt
      status: 200
      note: SPA shell, not a document
related:
  product_security: https://clarivate.com/information-security/product-security/
  security_standards: https://clarivate.com/information-security/summary-of-standards/
  information_security_hub: https://clarivate.com/information-security/
gap:
  finding: >-
    A one-line RFC 9116 /.well-known/security.txt on clarivate.com pointing Policy: at
    the responsible-disclosure page and Contact: at hackerone@clarivate.com would make
    an existing, funded program machine-discoverable. Today the program is invisible to
    every automated check.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/clarivate-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.