AlphaLoops FMCSA Carrier Data API · Vulnerability Disclosure

Alphaloops Vulnerability Disclosure

Vulnerability disclosure

AlphaLoops publishes a "Report a Vulnerability" section on its public security page inviting responsible disclosure by email, with a stated 24-hour response commitment. There is no security.txt served on any host, no bug-bounty program (HackerOne / Bugcrowd / Intigriti), and no published safe-harbor or scope statement.

AlphaLoops FMCSA Carrier Data API runs a coordinated vulnerability disclosure program on Hackerone.

fmcsa apisafer web apidot lookupcarrier datafreighttruckingmotor carrierfleet intelligencesales intelligencemcp servercontact enrichmentriskfraud
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-11'
method: searched
probe: true
source: https://runalphaloops.com/security
description: >-
  AlphaLoops publishes a "Report a Vulnerability" section on its public security page inviting
  responsible disclosure by email, with a stated 24-hour response commitment. There is no
  security.txt served on any host, no bug-bounty program (HackerOne / Bugcrowd / Intigriti),
  and no published safe-harbor or scope statement.

program:
  exists: true
  type: email-disclosure
  formal_policy_published: false
  bug_bounty: false
  bounty_platform: null
  safe_harbor_published: false
  scope_published: false
  disclosure_page: https://runalphaloops.com/security
  contact_email: security@runalphaloop.com
  response_commitment: 24 hours
  verbatim: >-
    "Found a security issue? We appreciate responsible disclosure. Please email us with details
    and we'll respond within 24 hours. security@runalphaloop.com"

# DEFECT WORTH REPORTING TO THE PROVIDER — the published security contact uses the domain
# "runalphaloop.com" (SINGULAR "loop"), while the company, its site, its API and its MCP server
# all live on "runalphaloops.com" (PLURAL). The same singular-domain address appears as the
# general contact (hello@runalphaloop.com) in the site footer and in the OpenAPI info.contact
# block. If runalphaloop.com is not a domain AlphaLoops controls and routes, the advertised
# vulnerability-reporting channel does not reach them.
anomalies:
  - kind: contact-domain-mismatch
    severity: high
    detail: >-
      Security contact security@runalphaloop.com and general contact hello@runalphaloop.com use
      runalphaloop.com (singular), but every operational host is runalphaloops.com (plural).
    observed_at:
      - https://runalphaloops.com/security
      - https://runalphaloops.com/pricing
      - https://runalphaloops.com/openapi.json
    remediation: >-
      Confirm runalphaloop.com is owned and receiving mail, or correct the published addresses
      to @runalphaloops.com across the security page, site footer and OpenAPI info.contact.

security_txt:
  served: false
  probed:
    - url: https://runalphaloops.com/.well-known/security.txt
      http_status: 200
      result: miss
      note: SPA catch-all returns the marketing HTML shell for every path; not a security.txt.
    - url: https://api.runalphaloops.com/.well-known/security.txt
      http_status: 404
      result: miss
    - url: https://mcp-freight.runalphaloops.com/.well-known/security.txt
      http_status: 404
      result: miss

evidence:
  - url: https://runalphaloops.com/security
    http_status: 200
    kind: disclosure page
    keywords:
      - Report a Vulnerability
      - responsible disclosure
      - security@