Clerk

Clerk

Top 100K site
VDPActive

Program Details

Clerk asks researchers to avoid privacy violations and disruption to production systems, stay within the published scope, and keep findings confidential until Clerk has had 90 days to resolve the issue. In return, Clerk commits to not pursue or support legal action related to the research, and to confirm receipt of a report within 3 business days.

Allows Disclosure
Yes
Disclosure Window
90 days
Response SLA
3 business days

Rules & Testing

Excluded Methods

DosSocial EngineeringPhishingPhysical Access

Scope (5 targets)

  • https://dashboard.clerk.com web
  • https://accounts.clerk.com web
  • https://api.clerk.com api
  • https://clerk.clerk.com web
  • Production instances created on https://dashboard.clerk.com web

Out of Scope

https://clerk.com, Any services hosted by third party providers, Findings in development or staging instances created on https://dashboard.clerk.com, Findings from applications or systems not listed in the scope, UI and UX bugs and spelling mistakes

Security

Preferred Languages
English

security.txt

Contact
https://clerk.com/docs/guides/how-clerk-works/security/vulnerability-disclosure-policy, mailto:[email protected]
Policy
https://clerk.com/docs/guides/how-clerk-works/security/vulnerability-disclosure-policy
Languages
en
Expires
Dec 1, 2026
View raw security.txt →