Security & responsible disclosure
ClearKey Solutions LLC · Effective August 3, 2026 · Last updated August 3, 2026 by Caleb Owen, Managing Member · Reviewed at least annually
This page describes how to report a security vulnerability in Citeory and summarizes the written information-security program maintained by ClearKey Solutions LLC. Citeory is designed to hold a minimal set of personal information — account email addresses and users' citation libraries — and the controls described below are proportionate to that data.
Reporting a vulnerability
Vulnerability reports should be sent to [email protected]. If the security address is unavailable, [email protected] reaches the same operator. The machine-readable version of this notice is published at /.well-known/security.txt (RFC 9116).
Reports should include, where available: the affected URL, endpoint, or component; steps to reproduce; and the impact as the reporter understands it. Proof-of-concept detail is appreciated and accelerates triage.
What to expect from us
| Step | Target |
|---|---|
| Acknowledgement | 3 business days |
| Triage and severity assessment | 7 days |
| Fix deployed, by severity | 72 hours (critical) · 14 days (high) · 60 days (medium) · 180 days (low) |
| Closure note back to you | with the fix |
Safe harbor
ClearKey Solutions LLC supports good-faith security research and will not pursue legal action in response to research conducted in accordance with this policy. Research is considered to be in good faith when it: uses accounts created by the researcher rather than accessing, modifying, or exfiltrating data belonging to others; does not degrade the service (no denial-of-service testing, and no volumetric scanning beyond what reproduction requires); does not involve social engineering of users or the operator; and allows a reasonable remediation window before any public disclosure. Researchers who wish to be credited when a fix is released will be acknowledged by name on request.
Scope
In scope: citeory.com, citeory.cksites.dev, the
API under /api/, the Word, Google Docs and Pages add-ins,
the Scout mobile app, and the browser extension. Out of scope: our providers'
own infrastructure (Azure, Cloudflare, Firebase, Stripe — report to them
directly), and findings that require an already-compromised device.
The security program
ClearKey Solutions LLC maintains written, dated information-security policies, reviewed at least annually, covering five areas. The internal documents contain operational detail (runbooks, infrastructure specifics) that is deliberately not published; the following is an accurate summary of each.
Vulnerability management
Vulnerabilities are identified continuously — automated dependency monitoring and a weekly scheduled audit of the full dependency tree, external reports through this page, regression test suites on every deploy, and periodic adversarial review (the most recent full red-team pass was July 2026). Findings are risk-ranked by severity, adjusted for actual reachability and blast radius in our deployment, and every fix lands with a regression test so the same hole cannot quietly reopen.
Patching
The deadlines in the table above are our internal patch SLA, measured to deployed in production, not merged. A critical issue that cannot be fixed same-day gets a mitigation within 24 hours. Exceptions require a written, time-boxed acceptance with a compensating control.
Incident response
We have a documented incident response process: severity definitions, containment and recovery steps, evidence preservation, and blameless post-mortems. If we become aware of a breach affecting your information, we will notify you and the appropriate authorities as required by law — the same commitment our Privacy Policy makes.
Disaster recovery
The primary database is backed up continuously with point-in-time restore capability, supplemented by periodic offline copies held separately from the production cloud account. The restore procedure is documented with defined recovery-point and recovery-time objectives, and is exercised in a scheduled restore drill.
Risk management
A standing risk register with a semi-annual assess-treat-accept review. Accepted risks are recorded decisions with revisit conditions, not things nobody noticed.
Architecture, briefly
All traffic is encrypted in transit. Identity is handled by a dedicated authentication provider, with tokens verified server-side on every request. No payment-card data touches ClearKey systems — payments are processed end-to-end by Stripe. Citations are produced by a deterministic rules engine; a single, disclosed AI component assists with parsing unstructured input and produces no citation output. An internal adversarial (red-team) review of the application was completed in July 2026, with all critical and high findings remediated and regression-tested.
© 2026 ClearKey Solutions LLC · Legal center · Privacy · Citeory