ClearPolicy

Security

Last updated: July 17, 2026

ClearPolicy, operated by Laconic Company LLC ("ClearPolicy," "we," "our," or "us"), takes the security of our service seriously. This page summarizes selected product integrity practices and how to report security vulnerabilities.

Our Terms of Service, Privacy Policy, and Data Processing Agreement continue to govern customer use of the service.

Digitally signed attestation certificates

When someone completes a document request electronically, your organization can download an attestation certificate PDF for that completion. That PDF includes the policy pages they completed against plus a certificate page with audit details (such as document version hash, recipient, timestamps, and technical evidence).

ClearPolicy digitally signs those electronic certificate PDFs with a ClearPolicy-controlled signing certificate before download. A valid digital signature helps confirm that the PDF file was issued by ClearPolicy and has not been altered after it was sealed. If the file is modified, common PDF signature checks will typically show the signature as invalid.

This digital signature is an issuer integrity seal on the certificate file. It is separate from the person's electronic signature or acknowledgment under ESIGN and UETA, which is captured in the product record (for example intent, typed name where applicable, timestamp, IP address, browser details, and document version). Paper-on-file completions do not receive an electronic attestation certificate or this digital seal.

Readers and validators may report the signing certificate as self-issued or not trusted by a public certificate authority. That does not by itself mean the file was changed; it means the trust path differs from a publicly trusted document-signing certificate. We do not claim qualified electronic signatures under eIDAS, Swiss ESigA compliance, or that every third-party validator will show a green trusted identity.

Vulnerability disclosure policy

We welcome reports of security vulnerabilities from security researchers and others acting in good faith. The sections below explain how to report a potential vulnerability, what is in scope, and what we ask of reporters. This is not a bug bounty program and does not create a contract, warranty, or commitment beyond what is stated here.

How to report

Email [email protected].

Please include, where practical:

  • A clear description of the issue and its potential impact
  • The product, URL, or component affected (for example, app, API, or website)
  • Steps to reproduce, or a proof of concept that does not harm systems or data
  • Any relevant screenshots, request/response samples, or logs (redact secrets)
  • Your preferred contact method if different from the sending address

Do not include passwords, API tokens, full payment card numbers, or other secrets unless we specifically request them through a secure channel.

For product support, billing, or general account questions, use [email protected] instead.

Scope

In scope (systems we operate for ClearPolicy):

Out of scope (unless we expressly invite testing in writing):

  • Customer organizations' own websites, networks, email, or devices
  • Third-party products and services we integrate with or rely on (for example, cloud providers, payment processors, email delivery, identity providers, or analytics), except where a ClearPolicy-controlled configuration clearly causes the issue
  • Social engineering, phishing, or physical attacks against our staff, contractors, or customers
  • Denial of service, volumetric attacks, spam, or intentional resource exhaustion
  • Automated mass scanning that degrades service availability or generates excessive traffic
  • Issues that require physical access to a device already unlocked or compromised
  • Reports limited to missing security headers, cookie flags, or TLS configuration without a demonstrated security impact
  • Theoretical issues without a practical path to impact, or problems only in outdated browsers or unsupported clients

If you are unsure whether something is in scope, describe it at a high level by email before deeper testing.

Rules of engagement

When researching or reporting issues under this policy, you must:

  • Act in good faith and avoid privacy violations, destruction of data, and interruption or degradation of our service
  • Not access, modify, or delete data that is not yours — including data belonging to other customer organizations, their people, or their documents
  • Not use a vulnerability to pivot into other systems, exfiltrate data beyond what is needed to demonstrate the issue, or maintain persistence
  • Not publicly disclose the vulnerability, exploit code, or sensitive details before we have had a reasonable opportunity to investigate and remediate (see Coordinated disclosure below)
  • Comply with applicable law. This policy does not authorize activity that is illegal in your jurisdiction or ours

If you accidentally access data that is not yours, stop testing that path, do not copy or share the data beyond the report, and tell us immediately in your email.

Coordinated disclosure

We prefer coordinated disclosure. After you report an issue, please give us a reasonable time to investigate and fix it before any public discussion, blog post, or conference talk. Many issues can be addressed within 90 days; complex cases may take longer. We will try to keep you informed of progress when you request updates.

If you plan to publish after remediation, we appreciate a chance to review technical details for accuracy and to confirm that secrets or customer data are not included.

What you can expect from us

  • We aim to acknowledge valid reports to [email protected] within a few business days (US Mountain Time)
  • We will investigate in-scope reports and prioritize based on severity and impact
  • We may ask for more information or a clearer reproduction path to complete the investigation
  • We will notify you when we believe the issue is resolved, if you provided a working contact address

No bug bounty. We do not currently offer money, swag, or other compensation for vulnerability reports. We may thank reporters who follow this policy; public credit is optional and only with your consent.

Good-faith research. If you make a good-faith effort to follow this policy, we will not pursue civil legal action against you or ask law enforcement to investigate you for that research under United States law solely for the conduct described in a report that complies with this policy. This is not a waiver of any rights regarding intentional harm, extortion, or activity outside this policy.

Customer security incidents

This page is for external vulnerability reports about ClearPolicy systems. If you are a ClearPolicy customer and need to report a security incident involving your organization's data, contact [email protected] or [email protected]. Incident notification obligations to customers are described in our Data Processing Agreement.

Machine-readable contact

Our security contact is also published at app.clearpolicy.app/.well-known/security.txt (RFC 9116), with discovery redirects from this site.

Changes

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the current version. Continued reporting under this page is subject to the version published at the time of your report.

Contact

Security reports: [email protected]
General support: [email protected]