AlgoVoi · Vulnerability Disclosure

Algovoi Co Uk Vulnerability Disclosure

Vulnerability disclosure

AlgoVoi runs a coordinated vulnerability disclosure process with a published contact, scope and response targets, but no paid bug bounty ("Not yet ... A formal paid bug bounty is on the roadmap" — security FAQ). Three hosts serve an RFC 9116 security.txt; the Policy URLs those files point at are both broken (a /AlgoVoi/compliance.html path that 404s and a GitHub INCIDENT_RESPONSE_PLAN.md that 404s), so the live policy text is the docs security page, which security.txt names in its Acknowledgments field.

AlgoVoi runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

PaymentsAgentic Commercex402A2AMCPStablecoinsCryptocurrencyBlockchainComplianceDigital SignaturePost-Quantum CryptographyVerificationFintechAgent-NativeAlgorandUnited Kingdom
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
alternatehttps://github.com/chopmob-cloud/AlgoVoi-Platform-Adapters/issues (non-sensitive only — "do not open a public GitHub issue" for security reports)
Contact
emailsecurity@algovoi.co.uk
Contact
languagesen

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
source: https://docs.algovoi.co.uk/security#coordinated-vulnerability-disclosure
description: >-
  AlgoVoi runs a coordinated vulnerability disclosure process with a published contact, scope and response targets,
  but no paid bug bounty ("Not yet ... A formal paid bug bounty is on the roadmap" — security FAQ). Three hosts serve an
  RFC 9116 security.txt; the Policy URLs those files point at are both broken (a /AlgoVoi/compliance.html path that 404s
  and a GitHub INCIDENT_RESPONSE_PLAN.md that 404s), so the live policy text is the docs security page, which security.txt
  names in its Acknowledgments field.
contact:
  email: security@algovoi.co.uk
  alternate: https://github.com/chopmob-cloud/AlgoVoi-Platform-Adapters/issues (non-sensitive only — "do not open a public GitHub issue" for security reports)
  languages: [en]
security_txt:
- {url: 'https://algovoi.co.uk/.well-known/security.txt', http_status: 200, expires: '2027-04-26T00:00:00Z', policy: 'https://algovoi.co.uk/AlgoVoi/compliance.html#disclosure', policy_status: 404, acknowledgments: 'https://docs.algovoi.co.uk/security', file: well-known/algovoi-co-uk-security.txt}
- {url: 'https://api.algovoi.co.uk/.well-known/security.txt', http_status: 200, expires: '2027-04-19T00:00:00Z', policy: 'https://github.com/chopmob-cloud/AlgoVoi-Platform-Adapters/blob/master/compliance/INCIDENT_RESPONSE_PLAN.md', policy_status: 404, file: well-known/algovoi-co-uk-api-security.txt}
- {url: 'https://cloud.algovoi.co.uk/.well-known/security.txt', http_status: 200, expires: '2027-04-19T00:00:00Z', policy: 'https://github.com/chopmob-cloud/AlgoVoi-Platform-Adapters/blob/master/compliance/INCIDENT_RESPONSE_PLAN.md', policy_status: 404, file: well-known/algovoi-co-uk-cloud-security.txt}
policy:
  url: https://docs.algovoi.co.uk/security
  section: Coordinated vulnerability disclosure
  statement: '"We commit to acknowledging receipt within 2 business days, providing a triage classification within 5 business days, and a remediation timeline appropriate to severity." The apex security.txt comments state tighter targets: "Acknowledgement target: 1 business day. Triage outcome target: 3 business days."'
  scope:
    in: ['*.algovoi.co.uk (operational subdomains)']
    out: [Customer-controlled wallets, Public on-chain data, Third-party services AlgoVoi depends on]
  safe_harbour: not stated
  disclosure_window: '"Please give us a reasonable time to respond before public disclosure." (security.txt)'
bug_bounty:
  program: none
  statement: '"Do you have a bug bounty programme? Not yet. We accept coordinated disclosure via security@algovoi.co.uk and follow the policy in our security.txt. A formal paid bug bounty is on the roadmap"'
  platforms_checked: [hackerone, bugcrowd, intigriti]
  platforms_result: none found
response_targets:
  acknowledgement: 2 business days (docs) / 1 business day (security.txt)
  triage: 5 business days (docs) / 3 business days (security.txt)
  support_page: '"Security disclosure (security@) — Acknowledged within 24 hours" (https://docs.algovoi.co.uk/support)'
related:
  agent_vulnerability_disclosure: 'https://agent-trust-bench.algovoi.co.uk/disclosure-policy — a separate AVD policy for findings the Agent Trust Bench makes about third-party agent stacks (30-day private notice, publication thresholds); not a program for reporting AlgoVoi''s own vulnerabilities.'
  penetration_testing: '"annual external pentest scheduled for Q4 2026"; self-conducted external audit 2026-05-27 published on the security page.'
evidence:
- {url: 'https://docs.algovoi.co.uk/security.md', http_status: 200, fetched: '2026-09-19'}
- {url: 'https://docs.algovoi.co.uk/support.md', http_status: 200, fetched: '2026-09-19'}
- {url: 'https://algovoi.co.uk/.well-known/security.txt', http_status: 200, fetched: '2026-09-19'}
- {url: 'https://algovoi.co.uk/AlgoVoi/compliance.html', http_status: 404, fetched: '2026-09-19', note: 'the security.txt Policy target; https://algovoi.co.uk/compliance.html (no /AlgoVoi/ prefix) is 200'}
- {url: 'https://github.com/chopmob-cloud/AlgoVoi-Platform-Adapters/blob/master/compliance/INCIDENT_RESPONSE_PLAN.md', http_status: 404, fetched: '2026-09-19'}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/algovoi-co-uk-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.