Last updated 22 May 2026

Vulnerability Disclosure

Claimsight welcomes good-faith security reports for the pilot platform.

How to report

Email suspected vulnerabilities to security@claimsight.io. Include the affected URL, account type, reproduction steps, impact, screenshots or logs where safe, and whether any personal data may be involved.

The machine-readable contact is published at /.well-known/security.txt.

Research boundaries

  • Use only accounts, API keys, claimant invites, and data that you are authorised to use.
  • Do not access, alter, delete, download, or disclose data that is not yours.
  • Do not run denial-of-service, social engineering, phishing, spam, physical, or destructive tests.
  • Stop immediately and report if you encounter customer or claimant data.

What to expect

  • Claimsight will acknowledge credible reports through the configured security contact route.
  • Reports are triaged by severity, exploitability, affected data, and customer impact.
  • Confirmed issues are remediated and tracked through the incident or vulnerability process as appropriate.
  • Public disclosure should be coordinated with Claimsight so affected customers and data subjects are protected.

Your session has expired

Refresh the page to continue. You may need to sign in again, and any unsaved changes on this page will be lost.