Security
Vulnerability Disclosure Policy
Last updated: August 6, 2026
ComplianceLayer welcomes reports of security vulnerabilities in our own systems. This policy explains what is in scope, what we ask of you, and what protection we extend to good-faith research.
This page is about vulnerabilities in ComplianceLayer. If you want to report unauthorized scanning of your infrastructure through our platform, or ask that your domain be excluded from scanning, see About ComplianceLayer scanning instead.
1. Scope
In scope:
compliancelayer.netand its subdomainsapi.compliancelayer.net
Out of scope:
- Third-party services we use but do not operate — report those to the vendor
- Findings that require physical access, a compromised device, or a privileged position on a user's network
- Social engineering of our staff, customers, or vendors
- Reports generated purely by automated scanners with no demonstrated impact
- Missing hardening headers, weak TLS ciphers, or similar configuration observations with no demonstrated exploit path
- Denial of service, volumetric testing, and resource exhaustion
2. Rules of engagement
To stay within this policy, please:
- Use only your own accounts and your own test data
- Stop as soon as you have confirmed a vulnerability — enough to demonstrate it, no further
- Never access, modify, delete, or exfiltrate data belonging to anyone else. If you encounter someone else's data, stop immediately and tell us what you saw so we can assess exposure
- Never degrade or disrupt the service for other users
- Never use social engineering, phishing, or physical intrusion
- Give us a reasonable opportunity to fix the issue before disclosing it publicly
3. Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized. We will not pursue or support legal action against you for that research, and if a third party brings action against you for work that was within this policy, we will make it known that your activity was authorized.
If you accidentally step outside the rules above while acting in good faith — you reached data you did not expect to reach, or you triggered an effect you did not intend — that does not by itself forfeit safe harbor, provided you stop, do not use or retain what you found, and tell us promptly.
This safe harbor covers ComplianceLayer's own systems only. It cannot and does not authorize testing against our customers' infrastructure or any third party's systems.
4. How to report
Email security@compliancelayer.net. A useful report includes:
- The affected host, endpoint, or component
- Steps to reproduce, precise enough that we can follow them
- What an attacker could actually do with it
- Any logs, requests, or screenshots that help — redact third-party data
Write in English if you can. Our published contact details are also available at /.well-known/security.txt.
5. What to expect
We acknowledge reports and will tell you what we conclude — whether we are treating the report as a vulnerability, and if so, roughly where the fix stands. If we decide something is not a vulnerability, we will explain why rather than close the thread silently.
We do not run a bug bounty program and we do not pay for reports. There is no reward, and no ranking or leaderboard. We would rather say that plainly than let anyone spend time on the assumption that one exists. We are glad to credit you by name in the fix if you want that.
6. Contact
Security vulnerabilities: security@compliancelayer.net
Unauthorized scanning and scan exclusion: abuse@compliancelayer.net
Everything else: support@compliancelayer.net