CLAWOLF welcomes good-faith reports that help protect CLAWOLF systems and users.
Before testing
- Test only systems that CLAWOLF identifies as in scope or that you are otherwise authorized to test.
- Do not access, alter, retain, or disclose customer data or personal information.
- Do not perform denial-of-service, destructive testing, social engineering, physical intrusion, spam, or automated testing that degrades service.
- Stop testing and report immediately if sensitive data is encountered.
- Use the minimum proof necessary to demonstrate the issue.
Reporting
Send a clear report to [email protected]. Include the affected asset, steps to reproduce, impact, relevant logs or screenshots, and a safe way to contact the reporter. Do not send exploit code or sensitive data through an unencrypted channel.
CLAWOLF's commitment
For research conducted in good faith and consistent with this policy, CLAWOLF will not initiate legal action solely because of that research. CLAWOLF will review the report, communicate when practicable, and work toward an appropriate resolution based on severity and scope.
This policy does not authorize testing of customer systems, third-party providers, or infrastructure that CLAWOLF does not control.