Last updated 22 May 2026
Vulnerability Disclosure
Claimsight welcomes good-faith security reports for the pilot platform.
How to report
Email suspected vulnerabilities to security@claimsight.io. Include the affected URL, account type, reproduction steps, impact, screenshots or logs where safe, and whether any personal data may be involved.
The machine-readable contact is published at /.well-known/security.txt.
Research boundaries
- Use only accounts, API keys, claimant invites, and data that you are authorised to use.
- Do not access, alter, delete, download, or disclose data that is not yours.
- Do not run denial-of-service, social engineering, phishing, spam, physical, or destructive tests.
- Stop immediately and report if you encounter customer or claimant data.
What to expect
- Claimsight will acknowledge credible reports through the configured security contact route.
- Reports are triaged by severity, exploitability, affected data, and customer impact.
- Confirmed issues are remediated and tracked through the incident or vulnerability process as appropriate.
- Public disclosure should be coordinated with Claimsight so affected customers and data subjects are protected.