Feature
Vulnerability Disclosure & Bug Bounty
A published path for reporting security issues.
5 providers
24 APIs
3 declared variants
A security.txt, VDP, or bug-bounty program gives researchers a defined way to report vulnerabilities. Signals a provider that expects and handles security findings.
5 API providers on the APIs.io network offer vulnerability disclosure & bug bounty. The highest-rated are Packagist, Cybereason, BeyondTrust, US Cyber Command, Axonius.
Providers
Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.
Strong 1 Solid coverage with minor gaps
Developing 1 Usable, with meaningful gaps to close
Thin 3 Limited public surface area
BeyondTrust
BeyondTrust is a cybersecurity company specializing in privileged access management (PAM) and vulnerability...
US Cyber Command
US Cyber Command (USCYBERCOM) is a Unified Combatant Command of the United States Armed Forces responsible ...
Axonius
Axonius is a cybersecurity asset management platform providing SaaS management, device discovery, and secur...
What Providers Actually Declared
This feature is a canonical term. These are the free-text strings
providers wrote in their own apis.yml that map onto it.
Joint Cybersecurity AdvisoriesSecurity advisories API aggregating FriendsOfPHP, GitHub Advisory Database, and PSA sourcesVulnerability Management
Scroll for all 3