Skip to content
Client Focus

Responsible Disclosure

Last updated: September 2026

A channel for reporting vulnerabilities in Client Focus operated systems.

1. Scope

This policy covers clientfocusllc.com and Client Focus operated systems.

2. How to report

Include a description, steps to reproduce and the potential impact. Encrypted reporting is available on request.

Send reports to security@clientfocusllc.com.

3. What to expect

Client Focus acknowledges reports within 3 business days, provides status updates and coordinates disclosure with the reporter.

4. Safe harbor

Client Focus will not pursue action against good faith research conducted within this policy's scope. Avoid accessing, modifying or disclosing data belonging to others, and stop testing if you encounter sensitive information.

5. Out of scope

Social engineering, physical attacks, denial of service, third-party services and automated scanner output without demonstrated impact are out of scope.

Talk with Client Focus about your digital asset program.

Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.