Skip to content

ClueBeat / Draft policies

Security

A pre-launch draft about website security and the limits of the planned service.

Draft for review ยท 27 September 2026

Draft for review; this is not a live reporting channel. ClueBeat has selected cluebeat.com and proposed meet@cluebeat.com as its public contact address. Mail delivery and replies are not yet verified. A working security-report route will be published before public launch. This website is a product demonstration, not an account portal, and this page does not imply a completed security audit or certification.

1. Report a security issue

A working report route will be published before the website goes live. No ClueBeat reporting address is active in this draft. Once that route is available, a useful report would include the affected URL, when you noticed the issue, its impact and safe steps to reproduce it. A small redacted example may help.

Do not include other people's personal information, live access tokens or passwords. If sensitive details are essential, first ask how to send them safely. We do not publish a guaranteed response time or a paid bug-bounty programme.

If you encounter information that should not be public, stop inspecting it. Do not download more records to prove that it exists.

2. What the current website does

  • The product screens and counters are illustrative, not live customer data.
  • The example rule input and pricing calculator run in the browser.
  • There is no enabled account login, monitoring submission or payment checkout on this website version.
  • Google Fonts supplies the typefaces. The website's own code, styles and mascot assets are delivered with the site.

Use the published HTTPS address when it becomes available. A local development preview is not a checkout address. The draft privacy notice describes information involved in browsing; it will be updated when a contact route is added.

3. Payment security

Paid subscriptions are intended to use Paddle's checkout. When enabled, payment entry should take place through that checkout, not by sending card details to ClueBeat. Payment questions can be directed to Paddle's buyer support.

Paddle publishes its own security information at security.paddle.com. A supplier's certification does not certify ClueBeat. We do not claim SOC 2, ISO 27001 or a completed independent penetration test for ClueBeat.

4. Using website monitoring safely

When the monitoring service opens, only submit pages you have a lawful right to monitor. A public URL does not remove copyright, privacy, contractual or access restrictions. Do not use monitoring to obtain someone else's private information or to bypass a login, paywall or access control without permission.

Do not include passwords, session cookies, API keys or confidential material in a URL or a support message. Page text, screenshots and alerts can contain information from the source page, so consider who should be allowed to see them before sharing.

Monitoring is not an emergency alarm or a guarantee that every change will be detected. A site can block requests, change its layout or become unavailable. An AI explanation can be wrong. Check the original evidence before making a consequential decision.

5. Product controls and assurance

The account-based product is still being prepared. We will describe its implemented access controls, storage protection, retention, service providers and incident-reporting process before accepting customer monitoring data. We will not present design goals as controls that have already passed testing.

A route for security-review questions will be published before customer monitoring data is accepted. We can then explain what is implemented and what remains to be verified. No uptime or recovery-time commitment is created by this page.

6. Responsible testing boundaries

A request to report a problem is not permission to attack the service or its providers. Keep testing limited, lawful and non-disruptive. Do not attempt denial of service, credential stuffing, phishing, data destruction, or access to another person's account. Do not test a third-party service under the assumption that ClueBeat can authorise it.

Please give us a reasonable opportunity to investigate before publishing details that would put people at risk. This request does not restrict lawful reporting to regulators or authorities.

7. Security updates

We will revise this page when the service or its verified controls change. If a confirmed incident creates a notification obligation, we will follow the applicable requirements. A working question and report route will appear before public launch.

Contact before launch

A working route for security reports and questions will appear here before publication.