If you have found a security issue in ClearList, please tell me. Email hello@clearlist.me. A real person reads it, and that person is me.
About the money, up front
I want to be straight with you before you spend an evening on this, rather than after.
ClearList does not have a bug bounty. Not because I think the work is worth nothing, but because I genuinely cannot afford one. ClearList is a very early stage startup run by one person, and there is no budget to pay for reports right now. I am sorry. Your time is worth something and I am asking for it anyway, which I know is a lot to ask.
If that changes, I will pay for reports, and I will go back and pay for the ones sent to me before there was any money. That is a promise I intend to keep rather than a nice thing to say.
What I can offer instead
- A reply from a human, normally within a few days.
- An honest answer about whether it is a real issue, including when it is not.
- A fix, and a note in the public changelog when it ships.
- Public credit on this page if you want it, or none at all if you would rather.
- A reference or an introduction if that is useful to you. Just ask.
What helps a report land
- What you did, step by step, and what happened.
- The URL or API route involved.
- What an attacker gets out of it. This matters more than the category name.
- Anything you are unsure about. A maybe is still worth sending.
A rough email beats a polished one that never gets written. Do not worry about the format.
Please do not
- Test against other people's sales or accounts. Use your own. Sign-up is free and takes a minute, and everything on ClearList belongs to a real person who is moving house.
- Run load tests, denial of service, or automated scanners heavy enough to affect anyone else's sale.
- Read, change, or delete data that is not yours. If you reach it by accident, stop and tell me.
- Publish the details before there has been a chance to fix it. See the timeline below.
Timeline
These are targets from one person, not guarantees from a team. If I slip, chase me.
- Acknowledgement within 5 days.
- An assessment of whether it is real, and how serious, within 14 days.
- A fix for anything serious as fast as I can manage. Recent security fixes have shipped within a day or two.
- Publish whenever you like after it is fixed, or after 90 days if I have gone quiet on you.
If you report in good faith
I will not pursue legal action against you, and I will not ask anyone else to, for testing that follows this page. If you are unsure whether something is in scope, email first and ask. I would much rather answer a question than receive an apology.
Thanks
People who have reported security issues to ClearList and agreed to be named will be listed here. If you have sent one and would like credit, or would like your name removed, email hello@clearlist.me.
Machine-readable version
The same contact details are published at https://clearlist.me/.well-known/security.txt in the RFC 9116 format.