Clozd · Vulnerability Disclosure

Clozd Vulnerability Disclosure

Vulnerability disclosure

Clozd runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

win-loss-analysiscustomer-feedbackdecision-intelligencesales-intelligencemarket-researchcompetitive-intelligencevoice-of-customerrevenue-intelligencesaasmcpagent-native
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@clozd.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: probed
probe: true
status: contact-only
policy: []
policy_published: false
bug_bounty:
  program: none-found
  platforms_checked:
  - HackerOne
  - Bugcrowd
  - Intigriti
contact:
- security@clozd.com
security_txt:
  present: false
  paths_checked:
  - https://www.clozd.com/.well-known/security.txt
  - https://clozd.com/.well-known/security.txt
  - https://app.clozd.com/.well-known/security.txt
  - https://mcp.clozd.com/.well-known/security.txt
  note: >-
    404 on the marketing hosts; the app and MCP hosts return an HTML SPA shell with status 200, which is
    not a security.txt.
disclosure_pages_checked:
- url: https://www.clozd.com/security
  http_status: 404
- url: https://www.clozd.com/security/responsible-disclosure
  http_status: 404
- url: https://www.clozd.com/responsible-disclosure
  http_status: 404
- url: https://www.clozd.com/vulnerability-disclosure
  http_status: 404
- url: https://www.clozd.com/trust
  http_status: 404
- url: https://www.clozd.com/compliance
  http_status: 404
evidence:
- source: DNS CAA record for clozd.com
  kind: dns-iodef
  value: 0 iodef "mailto:security@clozd.com"
  note: >-
    The only machine-readable security contact Clozd publishes. RFC 8659 iodef is a CA-incident reporting
    address, not a vulnerability disclosure policy, but it is a real, verifiable, published security inbox.
- source: https://trust.clozd.com
  kind: trust-center
  http_status: 200
  note: Vanta trust center exists; no public disclosure policy is linked from clozd.com.
assessment: >-
  Clozd publishes no vulnerability disclosure policy, no security.txt and no bug bounty program. A security
  contact address is discoverable only from the DNS CAA iodef record. This artifact records the contact and
  the verified absence of a policy — it is deliberately NOT wired to a `Security` pointer in apis.yml,
  because no security or disclosure policy page exists to point at.
recommendation: >-
  Publish /.well-known/security.txt (RFC 9116) on www.clozd.com and app.clozd.com with Contact,
  Policy, Preferred-Languages and Expires, and add a responsible-disclosure page linked from the trust
  center.
x-evidence:
  fetched: '2026-08-04'