Skip to content

Search is only available in production builds. Try building and previewing the site to test it out locally.

Incident Response

To report a security vulnerability or suspected breach:

  • Email: [email protected]
  • Subject: Security report: [brief description]
  • Include: steps to reproduce, affected component, and your contact information

We treat all security reports as confidential. Please do not disclose the issue publicly before we have had a chance to investigate and respond.

StepTimeline
AcknowledgementWithin 48 hours
Initial triageWithin 5 business days
Status updateWithin 10 business days
ResolutionDepends on severity
LevelExamplesTarget resolution
CriticalData breach, authentication bypass24–72 hours
HighPrivilege escalation, data exposure7 days
MediumInformation disclosure, CSRF30 days
LowMinor issues, hardening improvements90 days

If a security incident affects customer data, Claryn will notify affected organizations by email within 72 hours of confirmation. Notifications include:

  • What happened
  • What data was affected
  • What Claryn has done or is doing
  • Recommended actions for affected customers

Claryn will assist customers in meeting their own regulatory notification obligations (e.g., LGPD, GDPR) where applicable.