Responsible Disclosure Policy (original) (raw)

Last updated Feb 14, 2025

The security of our systems and user data is Anthropic’s top priority. We appreciate the work of security researchers acting in good faith in identifying and reporting potential vulnerabilities.

Purpose

At Anthropic, our mission is to ensure artificial intelligence benefits humanity. Central to this mission is our commitment to the security and integrity of our systems, services, and the data entrusted to us by our users and partners. We've established this responsible disclosure program to collaborate with security researchers who help identify potential vulnerabilities in our systems.

As part of our mission to advance safe and responsible AI development across the industry, we actively encourage researchers to work with other AI organizations. If you discover a vulnerability that affects multiple AI services, please submit separate reports to each affected organization. This helps ensure that all impacted services can properly assess and address the vulnerability.

Scope of Systems

This Policy covers all internet-facing information systems, applications, or websites owned, operated, or controlled by us, including any web or mobile applications hosted on those websites, including the Anthropic domain and related subdomains (collectively, “Information Systems”).

This Policy also does not cover any information systems, websites, or applications that are owned, operated, or controlled by any third party, including any service provider or contractor to the Company, even where under an Anthropic domain. You should comply with the responsible disclosure efforts for those other systems, websites, and applications.

Scope of Vulnerabilities

This Policy covers technical vulnerabilities that potentially exist on our Information Systems such as misconfigurations, CSRFs or cross site request forgeries, privilege escalation attacks, SQL Injection, XSS, and directory traversal attacks.

This Policy excludes the following vulnerabilities, subject to Anthropic’s discretion:

We welcome reports concerning safety issues, “jailbreaks,” and similar concerns so that we can enhance the safety and harmlessness of our models. Please report such issues to usersafety@anthropic.com with enough detail for us to replicate the issue.

How to Submit a Report

If you discover a security vulnerability in an Anthropic system, please promptly report it to us here. Include a detailed summary and any supporting details (logs, code, proofs of concept) to help us understand, validate, reproduce, and respond to it quickly.

At a minimum, you should be prepared to provide the following:

We ask that all reports be well-written, include only one vulnerability per report, and include any plans or intentions for public disclosure. The more detailed and clear the report, the more likely we will be able to investigate and respond effectively.

While we reserve final and sole discretion for whether you are acting in good faith and in accordance with this Policy, we will generally presume you are acting in good faith if you abide by this Policy for conducting security research and discovering potential vulnerabilities related to the Information Systems and agree to the following:

If you have any questions about this Policy or whether your research is consistent with these engagement guidelines, please contact disclosure@anthropic.com before proceeding.

Your Expectations of Us

All good-faith reports will be taken seriously. Upon promptly and responsibly reporting any potential vulnerability you have discovered, you can expect us to promptly evaluate your findings. If we determine (at our sole discretion) that a vulnerability exists, you can expect us to validate the existence of the vulnerability, to confirm the same with you, and to promptly take appropriate steps to address, mitigate, or remediate the vulnerability to the extent feasible. Finally, you can expect us to collaborate expeditiously with you to support timely and safe disclosure of your findings.

If you provide your contact information, our representatives may contact you for further information. Additionally, we will:

Safe Harbor

If you, in our sole determination, make a good faith effort to research and disclose vulnerabilities in accordance with this Policy and the above Research Guidelines, we will not pursue any legal action because of your research or responsible disclosure, subject to Anthropic’s compliance with applicable laws and legal obligations. To qualify for safe harbor, disclosures to us must be unconditional and may not involve extortion or threats.

Changes to this Policy

We reserve the right to make changes to this Policy at any time by publishing a new policy and amending the date of last update. Vulnerabilities disclosed prior to any update of this Policy will remain subject to the then-current policy in effect.