Solsten · Vulnerability Disclosure

12Traits Vulnerability Disclosure

Vulnerability disclosure

Solsten runs a coordinated vulnerability disclosure program on Hackerone.

CompanyAudience IntelligencePsychographicsConsumer InsightsAnalyticsArtificial IntelligenceGamingMarket ResearchPersonalizationBehavioral Data
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

12traits-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-05'
method: searched
source: https://solsten.io/data-privacy
name: Solsten vulnerability disclosure
summary: >-
  Solsten publishes a security contact address but not a vulnerability disclosure program. There is
  no /.well-known/security.txt on any host, no disclosure policy page, no safe-harbour statement, and
  no bug bounty on HackerOne, Bugcrowd or Intigriti. What exists is a single line on the Data Privacy
  page directing security questions to a named mailbox.
program: none
policy_url: null
security_txt: false
safe_harbor: false
bug_bounty:
  present: false
  platform: null
contacts:
- type: email
  value: security@solsten.io
  context: >-
    "Questions — For any question, please do not hesitate to reach out to security@solsten.io."
    Published in the Questions section of the Data Privacy page.
  evidence: https://solsten.io/data-privacy
practices_claimed:
- claim: >-
    "Penetration test and / or code review ('Security Check') once a year or after any major change
    in the system by external organization"
  evidence: https://solsten.io/data-privacy
  note: A stated internal practice, not a published report or attestation.
evidence:
- url: https://solsten.io/data-privacy
  status: 200
- url: https://solsten.io/.well-known/security.txt
  status: 404
- url: https://www.solsten.io/.well-known/security.txt
  status: 404
- url: https://api.solsten.io/.well-known/security.txt
  status: 404
- url: https://docs.api.solsten.io/.well-known/security.txt
  status: 404
- url: https://solsten.io/security
  status: 404
gaps:
- No RFC 9116 security.txt on any host — the machine-readable form of exactly the contact they already publish.
- No disclosure policy, response-time commitment, or safe-harbour language.
- The security contact is buried in a privacy page rather than surfaced on a security page.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/12traits-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.