← All pages

1. What the document is: Anthropic's "Responsible Disclosure Policy" — a bug-bounty/security-research policy (scope of systems, excluded vulnerability types, HackerOne-based submission process). Out of scope for this wiki's AI-training/data-licensing focus.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

Claude.ai – Vulnerability Disclosure Policy

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/Claude.ai/Vulnerability Disclosure Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2025-11-11 (only capture in this dataset)

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags on this page are LLM-assigned. Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.


Overview

1. What the document is: Anthropic’s “Responsible Disclosure Policy” — a bug-bounty/security-research policy (scope of systems, excluded vulnerability types, HackerOne-based submission process). Out of scope for this wiki’s AI-training/data-licensing focus.

2. Input rights: Not addressed.

3. Output restrictions: Not addressed — though notably, the policy explicitly excludes “red-teaming, adversarial testing of our models” and “content issues with model prompts and responses” from its security-vulnerability scope, redirecting such reports to a separate safety email instead.

4. Non-explicit predatory clauses: None found.

5. Regulatory references: None found.

6. Regional variation: Not addressed in this document.

7. Key risk to users: Not applicable — this is a security-research/bug-bounty policy, not a user-facing data-rights document. Worth noting for context: Anthropic explicitly invites cross-organization vulnerability reporting (“if you discover a vulnerability that affects multiple AI services, please submit separate reports to each affected organization”), a collaborative-disclosure stance not seen in OpenAI’s equivalent policy.

No AI-training, data-licensing, or output-restriction clauses found — out of scope for this wiki’s core risk categories.

Regulatory & Research Context

This policy’s explicit carve-out of “red-teaming, adversarial testing of our models” and “content issues with model prompts and responses” from its security-vulnerability scope is precisely the kind of boundary Davidson et al. (2026) flag as a “regulatory gray area” — their comparative analysis, which studies Anthropic directly, identifies uncertainty for legitimate security research as a recurring feature where Terms route AI-safety-adjacent testing away from the channels (like this one) that would otherwise protect it. Anthropic’s invitation for cross-organization reporting (“submit separate reports to each affected organization”) is a more collaborative disclosure stance than Davidson et al. (2026) describe for some other providers in their study, though it does not resolve the underlying gray area around adversarial model testing itself.


Changes Summary

DateWhat changed
2025-11-11Baseline and only version captured in this dataset (“Last updated Feb 14, 2025”).

Version History

2025-11-11

No AI-training, data-licensing, or output-restriction clauses found in this document.