Security & responsible disclosure

ClearKey Solutions LLC · Effective August 3, 2026 · Last updated August 3, 2026 by Caleb Owen, Managing Member · Reviewed at least annually

This page describes how to report a security vulnerability in Citeory and summarizes the written information-security program maintained by ClearKey Solutions LLC. Citeory is designed to hold a minimal set of personal information — account email addresses and users' citation libraries — and the controls described below are proportionate to that data.

Reporting a vulnerability

Vulnerability reports should be sent to security@citeory.com. If the security address is unavailable, help@citeory.com reaches the same operator. The machine-readable version of this notice is published at /.well-known/security.txt (RFC 9116).

Reports should include, where available: the affected URL, endpoint, or component; steps to reproduce; and the impact as the reporter understands it. Proof-of-concept detail is appreciated and accelerates triage.

What to expect from us

StepTarget
Acknowledgement3 business days
Triage and severity assessment7 days
Fix deployed, by severity72 hours (critical) · 14 days (high) · 60 days (medium) · 180 days (low)
Closure note back to youwith the fix

Safe harbor

ClearKey Solutions LLC supports good-faith security research and will not pursue legal action in response to research conducted in accordance with this policy. Research is considered to be in good faith when it: uses accounts created by the researcher rather than accessing, modifying, or exfiltrating data belonging to others; does not degrade the service (no denial-of-service testing, and no volumetric scanning beyond what reproduction requires); does not involve social engineering of users or the operator; and allows a reasonable remediation window before any public disclosure. Researchers who wish to be credited when a fix is released will be acknowledged by name on request.

Scope

In scope: citeory.com, citeory.cksites.dev, the API under /api/, the Word, Google Docs and Pages add-ins, the Scout mobile app, and the browser extension. Out of scope: our providers' own infrastructure (Azure, Cloudflare, Firebase, Stripe — report to them directly), and findings that require an already-compromised device.

The security program

ClearKey Solutions LLC maintains written, dated information-security policies, reviewed at least annually, covering five areas. The internal documents contain operational detail (runbooks, infrastructure specifics) that is deliberately not published; the following is an accurate summary of each.

Vulnerability management

Vulnerabilities are identified continuously — automated dependency monitoring and a weekly scheduled audit of the full dependency tree, external reports through this page, regression test suites on every deploy, and periodic adversarial review (the most recent full red-team pass was July 2026). Findings are risk-ranked by severity, adjusted for actual reachability and blast radius in our deployment, and every fix lands with a regression test so the same hole cannot quietly reopen.

Patching

The deadlines in the table above are our internal patch SLA, measured to deployed in production, not merged. A critical issue that cannot be fixed same-day gets a mitigation within 24 hours. Exceptions require a written, time-boxed acceptance with a compensating control.

Incident response

We have a documented incident response process: severity definitions, containment and recovery steps, evidence preservation, and blameless post-mortems. If we become aware of a breach affecting your information, we will notify you and the appropriate authorities as required by law — the same commitment our Privacy Policy makes.

Disaster recovery

The primary database is backed up continuously with point-in-time restore capability, supplemented by periodic offline copies held separately from the production cloud account. The restore procedure is documented with defined recovery-point and recovery-time objectives, and is exercised in a scheduled restore drill.

Risk management

A standing risk register with a semi-annual assess-treat-accept review. Accepted risks are recorded decisions with revisit conditions, not things nobody noticed.

Architecture, briefly

All traffic is encrypted in transit. Identity is handled by a dedicated authentication provider, with tokens verified server-side on every request. No payment-card data touches ClearKey systems — payments are processed end-to-end by Stripe. Citations are produced by a deterministic rules engine; a single, disclosed AI component assists with parsing unstructured input and produces no citation output. An internal adversarial (red-team) review of the application was completed in July 2026, with all critical and high findings remediated and regression-tested.

© 2026 ClearKey Solutions LLC · Legal center · Privacy · Citeory