Back to Home
Security & Responsibility
Found a vulnerability in Clareo?
We value security researchers who help make Clareo safer. Report responsibly and get rewarded for it.
How it works
We test, we fix, and we give credit. If you find a real vulnerability, we want to know before anyone else.
Send your report to [email protected] with:
- Clear description of the vulnerability
- Steps to reproduce
- Potential impact
- Evidence (screenshot, video, request)
We respond within 48 hours and triage within 7 days.
Rewards
CriticalAccess to another agency's data, authentication bypassR$ 300–500
HighPrivilege escalation, account data leakR$ 100–200
MediumLimited IDOR, information disclosureUp to 3 months free
LowMissing headers, minor misconfigurationsHall of Fame
Scope
In scope
- Web dashboard (app.clareo.app.br)
- Clareo API
- Clareo Fast (mobile app)
- Clareo MCP
- Subdomains *.clareo.app.br
Out of scope
- Brute-force or DDoS attacks
- Social engineering
- Testing on other real users' accounts
- Third-party vulnerabilities without proof of direct impact on Clareo
Rules
- 01Do not access, modify, or exfiltrate other users' data.
- 02Do not disclose the vulnerability before it is fixed.
- 03Researchers acting in good faith are protected — we will not take legal action against anyone who follows these rules.
Hall of Fame
We publicly recognize those who contribute to Clareo's security.
ResearcherVulnerabilityDate
KhurramDMARC · Clickjacking · TLS 1.0/1.1May 2026
Found something?