COMPLIANCE LAYER
  • Domain MonitoringCompliance ReportsExternal Risk API
  • MSP & MSSPCompliance TeamsCyber InsuranceCompliance FrameworksInsurance Audit Mapping
  • Pricing
  • Documentation
  • Integrations
  • Tools
  • Blog
Free Scan →Verify ReportSign inSign up

Security

Vulnerability Disclosure Policy

Last updated: August 6, 2026

ComplianceLayer welcomes reports of security vulnerabilities in our own systems. This policy explains what is in scope, what we ask of you, and what protection we extend to good-faith research.

This page is about vulnerabilities in ComplianceLayer. If you want to report unauthorized scanning of your infrastructure through our platform, or ask that your domain be excluded from scanning, see About ComplianceLayer scanning instead.

1. Scope

In scope:

  • compliancelayer.net and its subdomains
  • api.compliancelayer.net

Out of scope:

  • Third-party services we use but do not operate — report those to the vendor
  • Findings that require physical access, a compromised device, or a privileged position on a user's network
  • Social engineering of our staff, customers, or vendors
  • Reports generated purely by automated scanners with no demonstrated impact
  • Missing hardening headers, weak TLS ciphers, or similar configuration observations with no demonstrated exploit path
  • Denial of service, volumetric testing, and resource exhaustion

2. Rules of engagement

To stay within this policy, please:

  • Use only your own accounts and your own test data
  • Stop as soon as you have confirmed a vulnerability — enough to demonstrate it, no further
  • Never access, modify, delete, or exfiltrate data belonging to anyone else. If you encounter someone else's data, stop immediately and tell us what you saw so we can assess exposure
  • Never degrade or disrupt the service for other users
  • Never use social engineering, phishing, or physical intrusion
  • Give us a reasonable opportunity to fix the issue before disclosing it publicly

3. Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized. We will not pursue or support legal action against you for that research, and if a third party brings action against you for work that was within this policy, we will make it known that your activity was authorized.

If you accidentally step outside the rules above while acting in good faith — you reached data you did not expect to reach, or you triggered an effect you did not intend — that does not by itself forfeit safe harbor, provided you stop, do not use or retain what you found, and tell us promptly.

This safe harbor covers ComplianceLayer's own systems only. It cannot and does not authorize testing against our customers' infrastructure or any third party's systems.

4. How to report

Email security@compliancelayer.net. A useful report includes:

  • The affected host, endpoint, or component
  • Steps to reproduce, precise enough that we can follow them
  • What an attacker could actually do with it
  • Any logs, requests, or screenshots that help — redact third-party data

Write in English if you can. Our published contact details are also available at /.well-known/security.txt.

5. What to expect

We acknowledge reports and will tell you what we conclude — whether we are treating the report as a vulnerability, and if so, roughly where the fix stands. If we decide something is not a vulnerability, we will explain why rather than close the thread silently.

We do not run a bug bounty program and we do not pay for reports. There is no reward, and no ranking or leaderboard. We would rather say that plainly than let anyone spend time on the assumption that one exists. We are glad to credit you by name in the fix if you want that.

6. Contact

Security vulnerabilities: security@compliancelayer.net
Unauthorized scanning and scan exclusion: abuse@compliancelayer.net
Everything else: support@compliancelayer.net

Product
ToolsFree scanVerify ReportIntegrationsDocumentationRapidAPI
Solutions
MSP & MSSPCompliance TeamsCyber InsuranceInsurance Audit MappingCompliance Frameworks
Company
AboutPartnersCompareChangelogContact
Resources
StatusSecurity practicesReport a vulnerability
Legal
PrivacyTermsAUPRefundsDPAAbout our scanningRescans & disputes
© 2026 ComplianceLayer, Inc. All rights reserved. ·
System status