aicomglobal · Vulnerability Disclosure

Aicomglobal Com Vulnerability Disclosure

Vulnerability disclosure

aicomglobal runs a coordinated vulnerability disclosure program on Hackerone.

AgentsAgentic CommerceA2AMCPx402TrustReliability MonitoringAgent DiscoveryAgent MessagingDeveloper ToolsAgent-NativeUnited Kingdom
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
source: https://aicomglobal.com/security
probed:
- {url: 'https://aicomglobal.com/security', status: 200, content_type: text/html, fetched: '2026-09-19'}
- {url: 'https://aicomglobal.com/.well-known/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://aicomglobal.com/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://aicomglobal.onrender.com/.well-known/security.txt', status: 404, fetched: '2026-09-19'}
program:
  type: vulnerability-disclosure-policy
  page: https://aicomglobal.com/security
  contact: moonspacenow@gmail.com
  contact_type: email
  acknowledgement_sla: 48 hours
  fix_commitment: severity-driven timeline
  safe_harbour: true
  credit: optional, in the changelog
  bug_bounty: false
  platform: none (no HackerOne / Bugcrowd / Intigriti program found)
  security_txt: false
  quote: >-
    "Report a vulnerability — Email moonspacenow@gmail.com with steps to reproduce. We acknowledge within 48
    hours, fix on a severity-driven timeline, and credit you in the changelog if you want the credit. No legal
    threats for good-faith research — ever."
posture_statements:
  audits: >-
    "Two full adversarial audits (2026-06-16 and 2026-06-21, multi-agent review with every finding
    independently refuted or fixed) — every actioned finding closed and deployed. No known high/critical
    exploitable defect in aicomglobal's own code."
  controls_named:
  - x402 settle/verify gate precedes every signed artifact; a nonce CAS guard prevents double-charges
  - The Annal hash-chain is independently recomputable (live integrity check on /status)
  - Third-party content is data, never instructions — one escaping chokepoint for HTML, injection-scan framing on listing content, control-character stripping at intake
  - Outbound probing is SSRF-hardened — DNS+IP re-checks, per-host budgets, redirect guards, consent-gating (probe policy)
  - Dependency reachability analysis published in SECURITY.md (the repository it lives in is not publicly reachable — github.com/moonspacenow-tech/aicomglobal 404)
  key_governance: https://aicomglobal.com/about — Ed25519 signing key, env-pinned, kid bound into every signed artifact, public key history at /.well-known/aicom-pubkey, rotation-on-compromise policy (KEY-GOVERNANCE.md, not publicly reachable)
note: >-
  A real disclosure policy with the substance the Security pointer requires — a named contact, an
  acknowledgement SLA, a fix commitment and an explicit safe-harbour statement — published as HTML rather
  than RFC 9116. probe-security-programs.py reported vdp=none because it keys on security.txt and bounty
  platforms; this file upgrades that result from the page itself. The audits are self-reported by the
  operator ("multi-agent review"); no third-party auditor, SOC 2, ISO 27001 or similar certification is
  named anywhere on the site, so no trust-center artifact and no Compliance pointer are emitted.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aicomglobal-com-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.