Legal
Cluestick is operated by Brogan LLC. These documents govern its use and describe how data reaching the service is handled.
Reporting a vulnerability
Report suspected vulnerabilities to logan@brogan.io. Include enough detail to reproduce the issue. We aim to acknowledge a report within three business days.
Testing is in scope for systems Brogan LLC operates: the Cluestick web application, its API hosts, and the published Swift SDK. Testing against another company’s installation of Cluestick, or against any third-party service listed as a subprocessor, is out of scope.
Please avoid privacy violations, service degradation, and any destruction or exfiltration of data — access only accounts you own or have permission to test, and stop as soon as you have confirmed an issue. We will not pursue or support legal action against researchers who follow this policy in good faith. We do not operate a paid bug bounty.