If you discover a security vulnerability in Claros, please report it privately.
Email: security@claros.org
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
Claros is maintained by a solo developer. Honest expectations:
- Acknowledgment within 48 hours (usually faster)
- Assessment and fix timeline within 1 week
- Critical issues (data exposure, RCE) are prioritized above all other work
This policy covers the Claros engine code in this repository. For issues with the hosted Cloud service at app.claros.org, use the same email.
There is no bug bounty program at this time. Credit is given in release notes for responsibly disclosed vulnerabilities (unless you prefer to remain anonymous).
Only the latest release is supported with security patches. Running older versions is at your own risk - update regularly.