Halborn

Halborn is a blockchain and digital-asset cybersecurity firm that sells professional security services rather than a developer product. Its assurance practice covers smart contract assessments, Layer 1 protocol reviews, code security audits, web application and cloud infrastructure penetration testing, red team exercises, and custody and key management assessments; its advisory practice covers AI security, blockchain architecture, compliance readiness, risk assessment, technical due diligence and technical training for banks, exchanges, custodians, tokenization platforms, stablecoin issuers, DeFi protocols, central banks and blockchain infrastructure providers. Halborn publishes its engagement results as a public audit repository, discloses zero-day findings under its own CVE assignment scope as a CVE Numbering Authority, and maintains BVSS, the Blockchain Vulnerability Scoring System. As of August 2026 it publishes no public API, no developer portal and no machine-readable contract; its Halborn ONE client platform at one.halborn.com is an invitation-only customer portal.

Halborn is profiled on the APIs.io network. Tagged areas include Company, Security, Cybersecurity, Blockchain, and Smart Contracts.

Halborn’s developer surface includes engineering blog, support, and 14 more developer resources.

19.7/100 emerging ▬ flat Agent 3/100 human only Full breakdown ↓
scored 2026-08-25 · rubric v0.14.0
0 APIs
CompanySecurityCybersecurityBlockchainSmart ContractsSecurity AuditingPenetration TestingWeb3Vulnerability DisclosureComplianceFinancial ServicesProfessional Services

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-25 · rubric v0.14.0
Composite quality — 19.7/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 1.4 / 20
Access Clarity 8.7 / 20
Operational Transparency 1.7 / 13
Contract Governance 2.2 / 12
Discoverability 5.7 / 10
Agent readiness — 3/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
Documented Reversibility 0 / 6
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Delegated User Identity 0 / 6
Protected Resource Metadata 0 / 5
Registration Without a Human 0 / 6
Agentic Commerce Surface 0 / 5
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/halborn: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Pricing Plans 1

Published pricing tiers and plan structures.

Halborn Plans Pricing

0 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Halborn Rate Limits

0 limits

RATE LIMITS

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Halborn Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Halborn Vulnerability Disclosure

disclosure policy published

SECURITY

Halborn Trust Center

SOC 2, SOC 2, ISO/IEC 27001, NIST CSF 2.0

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 1

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 5

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: halborn
name: Halborn
description: Halborn is a blockchain and digital-asset cybersecurity firm that sells professional security services rather
  than a developer product. Its assurance practice covers smart contract assessments, Layer 1 protocol reviews, code security
  audits, web application and cloud infrastructure penetration testing, red team exercises, and custody and key management
  assessments; its advisory practice covers AI security, blockchain architecture, compliance readiness, risk assessment, technical
  due diligence and technical training for banks, exchanges, custodians, tokenization platforms, stablecoin issuers, DeFi
  protocols, central banks and blockchain infrastructure providers. Halborn publishes its engagement results as a public audit
  repository, discloses zero-day findings under its own CVE assignment scope as a CVE Numbering Authority, and maintains BVSS,
  the Blockchain Vulnerability Scoring System. As of August 2026 it publishes no public API, no developer portal and no machine-readable
  contract; its Halborn ONE client platform at one.halborn.com is an invitation-only customer portal.
image: https://www.halborn.com/og-image.jpeg
url: https://raw.githubusercontent.com/api-evangelist/halborn/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
x-tier: stub
x-tier-reason: harvest
specificationVersion: '0.23'
created: '2026-08-22'
modified: '2026-08-22'
tags:
- Company
- Security
- Cybersecurity
- Blockchain
- Smart Contracts
- Security Auditing
- Penetration Testing
- Web3
- Vulnerability Disclosure
- Compliance
- Financial Services
- Professional Services
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://www.halborn.com/
- type: Blog
  url: https://www.halborn.com/blog
- type: BlogRSS
  url: https://www.halborn.com/blog/feed.xml
- type: GitHubOrganization
  url: https://github.com/HalbornSecurity
- type: Support
  url: https://www.halborn.com/contact
- type: Login
  url: https://one.halborn.com/login
- type: TermsOfService
  url: https://www.halborn.com/terms
- type: PrivacyPolicy
  url: https://www.halborn.com/privacy
- type: LLMsTxt
  url: llms/halborn-llms.txt
- type: Security
  url: security/halborn-vulnerability-disclosure.yml
- type: VulnerabilityDisclosure
  url: security/halborn-vulnerability-disclosure.yml
- type: TrustCenter
  url: security/halborn-trust-center.yml
- type: Compliance
  url: security/halborn-trust-center.yml
- type: Conformance
  url: conformance/halborn-conformance.yml
- type: DomainSecurity
  url: security/halborn-domain-security.yml
- type: Packages
  url: packages/halborn-packages.yml
x-enrichment:
  date: '2026-08-22'
  status: enriched
  artifacts_added: 9
  pass: local-v1
x-coverage:
  state: none
  reason: no-developer-program
  detail: 'Halborn sells blockchain security assessments as professional services and ships no developer product: its 1,020-URL
    sitemap contains no /developers, /docs or /api section, docs.halborn.com and api.halborn.com do not resolve at all, and
    the only authenticated surface — Halborn ONE at one.halborn.com — is an invitation-only client portal whose login page
    says "Contact your local org-owner for an invitation". It does publish a real llms.txt, which lists services, industries,
    reports and RSS feeds and names no API.'
  evidence:
  - url: https://www.halborn.com/llms.txt
    status: 200
  - url: https://www.halborn.com/openapi.json
    status: 404
  - url: https://docs.halborn.com/
    status: 0
  - url: https://one.halborn.com/openapi.json
    status: 404
  - url: https://www.halborn.com/.well-known/agent-card.json
    status: 404
  checked: '2026-08-22'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/halborn"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/halborn/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/halborn/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.