ADVANCE.AI · Vulnerability Disclosure

Advanceai Vulnerability Disclosure

Vulnerability disclosure

ADVANCE.AI runs a coordinated vulnerability disclosure program on Hackerone.

CompanyIdentity VerificationKYCKYBAMLFraud PreventionFace RecognitionLiveness DetectionOCRDocument VerificationRisk ManagementArtificial IntelligenceFintechSingapore
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-07'
method: searched
source: https://advance.ai/security-compliance/
docs: https://advance.ai/security-compliance/
summary: >-
  ADVANCE.AI publishes a dedicated Security & Compliance page with a named security contact
  address, and describes a standing internal security team, security risk assessment practice and
  security research function. It does NOT publish an RFC 9116 security.txt, a written coordinated
  disclosure policy, safe-harbour language, a response-time commitment, or a bug bounty programme.
security_contact:
  email: security@advance.ai
  published_at: https://advance.ai/security-compliance/
  verbatim: 'If you have any inquiries please reach out to us at security@advance.ai'
  http_status: 200
  fetched: '2026-09-07'
security_txt:
  present: false
  probed:
  - {url: 'https://advance.ai/.well-known/security.txt', status: 404}
  - {url: 'https://api.advance.ai/.well-known/security.txt', status: 404}
  - {url: 'https://doc.advance.ai/.well-known/security.txt', status: 404}
  note: >-
    The contact exists but is only discoverable by a human reading an HTML marketing page. Adding
    an RFC 9116 file at /.well-known/security.txt naming this same address would make an existing
    commitment machine-discoverable at essentially zero cost. This is the single cheapest security
    improvement available to ADVANCE.AI.
disclosure_policy:
  published: false
  safe_harbour: false
  response_sla: false
  pgp_key: false
bug_bounty:
  program: none_found
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  note: No programme found on the public site or in search.
security_program:
  team: >-
    "Since 2016 our dedicated security team has been safeguarding ADVANCE.AI and our partners."
  practices_described:
  - Security compliance function
  - Security Risk Assessment (SRA) performed by a security assessor across systems, HR policies and firewall configuration
  - Security research team covering big-data security and privacy, cloud security, social-network security, security predictive analytics, cyber-physical systems, and trust/privacy/cybersecurity risk
  note: Described as capability, not as a customer-facing disclosure process.
transport_security:
  detail: See security/advanceai-domain-security.yml (TLS 1.3 on all three hosts, HSTS on advance.ai and doc.advance.ai, SPF and DMARC p=quarantine present, DNSSEC and CAA absent).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/advanceai-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.