1. What the document is: Anthropic's "Responsible Disclosure Policy" — a bug-bounty/security-research policy (scope of systems, excluded vulnerability types, HackerOne-based submission process). Out of scope for this wiki's AI-training/data-licensing focus.
What this wiki found — complete, every page
Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.
Claude.ai – Vulnerability Disclosure Policy
Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present
GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive
genai-euproject across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.
Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:
Source: sources/GenGA/Claude.ai/Vulnerability Disclosure Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source)
Last updated: 2025-11-11 (only capture in this dataset)
Note on methodology: No pre-computed
risk_score/keywordfields exist for this source. Keyword tags on this page are LLM-assigned. Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (seemethodology.md§4) — no page, GenGA included, computes or displays a numeric risk score.
Overview
1. What the document is: Anthropic’s “Responsible Disclosure Policy” — a bug-bounty/security-research policy (scope of systems, excluded vulnerability types, HackerOne-based submission process). Out of scope for this wiki’s AI-training/data-licensing focus.
2. Input rights: Not addressed.
3. Output restrictions: Not addressed — though notably, the policy explicitly excludes “red-teaming, adversarial testing of our models” and “content issues with model prompts and responses” from its security-vulnerability scope, redirecting such reports to a separate safety email instead.
4. Non-explicit predatory clauses: None found.
5. Regulatory references: None found.
6. Regional variation: Not addressed in this document.
7. Key risk to users: Not applicable — this is a security-research/bug-bounty policy, not a user-facing data-rights document. Worth noting for context: Anthropic explicitly invites cross-organization vulnerability reporting (“if you discover a vulnerability that affects multiple AI services, please submit separate reports to each affected organization”), a collaborative-disclosure stance not seen in OpenAI’s equivalent policy.
No AI-training, data-licensing, or output-restriction clauses found — out of scope for this wiki’s core risk categories.
Regulatory & Research Context
This policy’s explicit carve-out of “red-teaming, adversarial testing of our models” and “content issues with model prompts and responses” from its security-vulnerability scope is precisely the kind of boundary Davidson et al. (2026) flag as a “regulatory gray area” — their comparative analysis, which studies Anthropic directly, identifies uncertainty for legitimate security research as a recurring feature where Terms route AI-safety-adjacent testing away from the channels (like this one) that would otherwise protect it. Anthropic’s invitation for cross-organization reporting (“submit separate reports to each affected organization”) is a more collaborative disclosure stance than Davidson et al. (2026) describe for some other providers in their study, though it does not resolve the underlying gray area around adversarial model testing itself.
Changes Summary
| Date | What changed |
|---|---|
| 2025-11-11 | Baseline and only version captured in this dataset (“Last updated Feb 14, 2025”). |
Version History
2025-11-11
- Explicit AI clause: NO
- Non-explicit predatory: NO
- Flagged keywords: (none)
No AI-training, data-licensing, or output-restriction clauses found in this document.