How do I report a security vulnerability?
How to report a security vulnerability to Clean Smarts. Limited, discretionary recognition only—we do not run an active bug bounty program.
Clean Smarts maintains a Vulnerability Disclosure Policy so researchers and customers can report security issues responsibly.
We are not running an active bug bounty program and do not solicit outside testing. Unsolicited, good-faith reports that follow this policy are still accepted. Monetary awards are uncommon, discretionary, and not guaranteed.
We do not publicly confirm or discuss open security issues until we have investigated and addressed them.
How to Report
Email support@cleansmarts.com with subject Security Vulnerability.
Include:
- Short impact summary (what an attacker could do, and to whom)
- Affected product surface (web app, marketing site, mobile app, API) and endpoints if known
- Step-by-step reproduction, including environment and any test accounts you used
- Proof of concept limited to what is needed to demonstrate the issue (redact secrets and customer data)
- Optional remediation notes
One issue per email unless a chain is required to show impact. Incomplete scanner dumps without a concrete PoC are likely to be closed without follow-up.
What We Will Do
Targets, not guarantees:
|
Stage |
Target |
|---|---|
|
Acknowledgment |
Within 5 business days |
|
Initial assessment |
Within 15 business days when capacity allows |
|
Further updates |
As needed until we close the report |
We may close reports as duplicate, out of scope, informational, or accepted risk without further discussion.
Scope
Accepted for review when impact is clear:
- Clean Smarts production web app and API on
*.cleansmarts.com - Clean Smarts marketing site on domains we operate
- Current Clean Smarts iOS / Android apps
- Flaws that can expose or alter another customer’s data, escalate privilege, or take over accounts
Not accepted / not rewarded:
- Third-party services we use but do not operate (e.g. WorkOS, Mailgun, Vonage/Nexmo, Firebase, payment processors). Report those to the vendor.
- Staging or ephemeral environments unless we explicitly invite testing
- Social engineering, phishing, physical attacks, or office/corporate SaaS not listed above
- Denial of service, spam, or anything that degrades availability
- Theoretical findings, missing headers, TLS/mail preference issues, public files (
robots.txt), login-page enumeration, policy debates (password rules, rate limits, email verification) without a working unauthorized-access PoC - CVE or library version reports without an exploit specific to our implementation
- Self-XSS, CSRF on logout/anonymous forms, non-sensitive cookie flags, clickjacking without a sensitive-action PoC
- Anything requiring physical access to a device or a pre-compromised victim machine
If unsure whether something is in scope, ask before testing.
Rules for Testing
Only test if you can follow all of these:
- Use only accounts and data you own. Do not access, copy, modify, or destroy anyone else’s data.
- If you inadvertently touch another party’s data: stop, do not retain it, and declare it in your report.
- No DoS, flooding, lockout abuse, or aggressive automated scanning. Light, low-rate tooling tied to a specific hypothesis is the maximum we tolerate; noisy scanning may get your IP blocked.
- No social engineering of employees, customers, contractors, or vendors.
- Prove impact with a minimal PoC—then stop. Do not pivot, persist, or expand access.
- Follow applicable law.
Mark research traffic when practical: X-CS-Vulnerability-Report: <your-email>.
Safe Harbor
If you report in good faith and comply with this policy:
- Clean Smarts authorizes security research against in-scope assets using methods that do not violate the rules above.
- We will not pursue civil action or refer you for criminal prosecution for activity this policy authorizes.
- Safe harbor does not cover out-of-scope targets, intentional access to others’ data, DoS, social engineering, physical attacks, or public disclosure before we agree.
If you are unsure an action is allowed, email us before doing it.
Disclosure
- Do not publish or share the issue until we confirm it is fixed or we explicitly agree disclosure is OK—except as required by law.
- Default coordinated window: 90 days from our acknowledgment, or until we notify you a fix is live—whichever comes first. We may ask for more time on complex fixes.
- After that window, public write-ups must omit customer data and any details we ask you to withhold.
Recognition and Payment
Most valid reports receive thanks and optional public credit (with your consent) only.
A monetary award is rare and entirely at Clean Smarts’ discretion. There is no reward schedule, no severity payout table, and no entitlement to payment because a report is valid. Duplicate, out-of-scope, low-impact, or previously known issues are not paid.
If we do offer an amount, we will say so in writing and give you a reference number. Payment then requires an invoice (payee name and address, reference number, date, exact amount) plus any tax forms we request (e.g. W-9 / W-8BEN). We accept PayPal, US ACH, or wire when an award is offered.
Employees, contractors, and their immediate family are ineligible for payment.
Terms
- Parties: you and Clean Smarts Co. (“Clean Smarts”).
- By submitting a report you grant Clean Smarts a worldwide, royalty-free, non-exclusive license to use the submission to investigate and remediate.
- Only the first valid report of an issue we had not already identified is considered for any recognition; earliest valid report wins ties.
- Eligibility for any recognition or payment is solely Clean Smarts’ decision and is final.
- We may change or end this policy at any time. Updates apply to new testing and new reports after publication.
- Keep your contact email current if you expect a reply.
Confidentiality
Until coordinated disclosure is complete, treat non-public details as confidential and use them only to work with Clean Smarts. Do not share exploit details or customer data with third parties without our written consent (except your attorney, or as required by law).