Last updated: 24 June 2026
Responsible disclosure policy
Security is a primary design constraint for clmSpace, operated by Rated Counsel Limited, and we value the work of researchers who help us keep it strong. This policy explains how to report a vulnerability in good faith, the safe harbour we offer when you follow it, and what you can expect from us in return. It complements the controls described in our security white paper and the standards in our acceptable use policy.
Good-faith safe harbour
If you make a good-faith effort to comply with this policy during your research, we will treat your activity as authorised, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. We consider research conducted under this policy to be authorised under the relevant computer-misuse and anti-circumvention laws, and we will say so if a third party raises a concern about research that genuinely followed these rules. If legal action is initiated by a third party against you for activity that complied with this policy, we will make this authorisation known.
How to report
Email security@clmspace.com with a clear description of the issue. A helpful report includes:
- The type of issue and the part of the Service or site it affects.
- Steps to reproduce, with any proof-of-concept, request or response detail, and screenshots that help us confirm it.
- The potential impact as you see it, and any suggested remediation.
- A way to contact you, so we can keep you informed and credit you if you wish.
Please send reports in English where you can, and give us a reasonable opportunity to resolve the issue before sharing details publicly so that customers stay protected. We are happy to coordinate timing and credit with you.
Research guidelines
To keep your testing within the safe harbour, please:
- Act in good faith, avoid privacy violations, and stop as soon as you have confirmed a vulnerability.
- Only ever access, modify, or interact with your own accounts and test data, and never another customer’s data.
- Keep any data you encounter confidential, and delete it once your report is submitted.
- Use only your own test accounts, and report findings to us rather than retaining or sharing them.
- Limit testing to a single proof-of-concept and keep request volumes low so that availability is preserved for other customers.
Please keep testing to your own tenant and accounts, use techniques that preserve the integrity and availability of the Service for everyone, and respect the boundaries of the underlying AI models and their safety controls. Activities that protect customers and the Service, such as avoiding bulk data access, social engineering of our staff or customers, and physical access attempts, keep you within this policy.
What to expect from us
- We acknowledge reports within 2 business days.
- We triage and validate the issue, assign a severity, and keep you informed through triage, fix, and coordinated disclosure.
- We remediate on a timeline driven by severity, prioritising issues that most affect confidentiality, integrity, and availability.
- We are glad to credit researchers who would like recognition once a fix is in place.
Scope
This policy covers the clmSpace Service and the clmspace.com site operated by Rated Counsel Limited. Issues in the underlying platforms we build on (such as Microsoft Azure, Anthropic, Neon, and Vercel) are best reported to those providers under their own programmes; we are happy to help route a report to the right place. If you are unsure whether something is in scope, email us and ask.
Contact
Report a vulnerability or ask a question at security@clmspace.com. For general misuse or abuse concerns, see our acceptable use policy.