Back to Home

Security & Responsibility

Found a vulnerability in Clareo?

We value security researchers who help make Clareo safer. Report responsibly and get rewarded for it.

How it works

We test, we fix, and we give credit. If you find a real vulnerability, we want to know before anyone else.

Send your report to [email protected] with:

  • Clear description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Evidence (screenshot, video, request)

We respond within 48 hours and triage within 7 days.

Rewards

CriticalAccess to another agency's data, authentication bypassR$ 300–500
HighPrivilege escalation, account data leakR$ 100–200
MediumLimited IDOR, information disclosureUp to 3 months free
LowMissing headers, minor misconfigurationsHall of Fame

Scope

In scope
  • Web dashboard (app.clareo.app.br)
  • Clareo API
  • Clareo Fast (mobile app)
  • Clareo MCP
  • Subdomains *.clareo.app.br
Out of scope
  • Brute-force or DDoS attacks
  • Social engineering
  • Testing on other real users' accounts
  • Third-party vulnerabilities without proof of direct impact on Clareo

Rules

  • 01Do not access, modify, or exfiltrate other users' data.
  • 02Do not disclose the vulnerability before it is fixed.
  • 03Researchers acting in good faith are protected — we will not take legal action against anyone who follows these rules.

Hall of Fame

We publicly recognize those who contribute to Clareo's security.

ResearcherVulnerabilityDate
KhurramDMARC · Clickjacking · TLS 1.0/1.1May 2026

Found something?

Report it now.

[email protected]