aicomglobal · Vulnerability Disclosure
Aicomglobal Com Vulnerability Disclosure
Vulnerability disclosure
aicomglobal runs a coordinated vulnerability disclosure program on Hackerone.
AgentsAgentic CommerceA2AMCPx402TrustReliability MonitoringAgent DiscoveryAgent MessagingDeveloper ToolsAgent-NativeUnited Kingdom
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-19'
method: searched
source: https://aicomglobal.com/security
probed:
- {url: 'https://aicomglobal.com/security', status: 200, content_type: text/html, fetched: '2026-09-19'}
- {url: 'https://aicomglobal.com/.well-known/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://aicomglobal.com/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://aicomglobal.onrender.com/.well-known/security.txt', status: 404, fetched: '2026-09-19'}
program:
type: vulnerability-disclosure-policy
page: https://aicomglobal.com/security
contact: moonspacenow@gmail.com
contact_type: email
acknowledgement_sla: 48 hours
fix_commitment: severity-driven timeline
safe_harbour: true
credit: optional, in the changelog
bug_bounty: false
platform: none (no HackerOne / Bugcrowd / Intigriti program found)
security_txt: false
quote: >-
"Report a vulnerability — Email moonspacenow@gmail.com with steps to reproduce. We acknowledge within 48
hours, fix on a severity-driven timeline, and credit you in the changelog if you want the credit. No legal
threats for good-faith research — ever."
posture_statements:
audits: >-
"Two full adversarial audits (2026-06-16 and 2026-06-21, multi-agent review with every finding
independently refuted or fixed) — every actioned finding closed and deployed. No known high/critical
exploitable defect in aicomglobal's own code."
controls_named:
- x402 settle/verify gate precedes every signed artifact; a nonce CAS guard prevents double-charges
- The Annal hash-chain is independently recomputable (live integrity check on /status)
- Third-party content is data, never instructions — one escaping chokepoint for HTML, injection-scan framing on listing content, control-character stripping at intake
- Outbound probing is SSRF-hardened — DNS+IP re-checks, per-host budgets, redirect guards, consent-gating (probe policy)
- Dependency reachability analysis published in SECURITY.md (the repository it lives in is not publicly reachable — github.com/moonspacenow-tech/aicomglobal 404)
key_governance: https://aicomglobal.com/about — Ed25519 signing key, env-pinned, kid bound into every signed artifact, public key history at /.well-known/aicom-pubkey, rotation-on-compromise policy (KEY-GOVERNANCE.md, not publicly reachable)
note: >-
A real disclosure policy with the substance the Security pointer requires — a named contact, an
acknowledgement SLA, a fix commitment and an explicit safe-harbour statement — published as HTML rather
than RFC 9116. probe-security-programs.py reported vdp=none because it keys on security.txt and bounty
platforms; this file upgrades that result from the page itself. The audits are self-reported by the
operator ("multi-agent review"); no third-party auditor, SOC 2, ISO 27001 or similar certification is
named anywhere on the site, so no trust-center artifact and no Compliance pointer are emitted.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aicomglobal-com-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.