Feature
Vulnerability Disclosure & Bug Bounty
A published path for reporting security issues.
5 providers
6 APIs
3 declared variants
A security.txt, VDP, or bug-bounty program gives researchers a defined way to report vulnerabilities. Signals a provider that expects and handles security findings.
5 API providers on the APIs.io network offer vulnerability disclosure & bug bounty. The highest-rated are BeyondTrust, Packagist, US Cyber Command, Cybereason, Axonius.
Providers
Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.
Developing 2 Usable, with meaningful gaps to close
Thin 3 Limited public surface area
US Cyber Command
US Cyber Command (USCYBERCOM) is a Unified Combatant Command of the United States Armed Forces responsible ...
Cybereason
Cybereason is an enterprise cybersecurity company (now part of LevelBlue) that provides a defense platform ...
Axonius
Axonius is a cybersecurity asset management platform providing SaaS management, device discovery, and secur...
What Providers Actually Declared
This feature is a canonical term. These are the free-text strings
providers wrote in their own apis.yml that map onto it.
Joint Cybersecurity AdvisoriesSecurity advisories API aggregating FriendsOfPHP, GitHub Advisory Database, and PSA sourcesVulnerability Management
Scroll for all 3