AlphaLoops FMCSA Carrier Data API · Vulnerability Disclosure

Alphaloops Vulnerability Disclosure

Vulnerability disclosure

AlphaLoops publishes a "Report a Vulnerability" section on its public security page inviting responsible disclosure by email, with a stated 24-hour response commitment. There is no security.txt served on any host, no bug-bounty program (HackerOne / Bugcrowd / Intigriti), and no published safe-harbor or scope statement.

AlphaLoops FMCSA Carrier Data API runs a coordinated vulnerability disclosure program on Hackerone.

fmcsa apisafer web apidot lookupcarrier dataFreightTruckingmotor carrierfleet intelligenceSales IntelligenceMCP ServerContact EnrichmentRiskFraud
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-11'
method: searched
probe: true
source: https://runalphaloops.com/security
description: >-
  AlphaLoops publishes a "Report a Vulnerability" section on its public security page inviting
  responsible disclosure by email, with a stated 24-hour response commitment. There is no
  security.txt served on any host, no bug-bounty program (HackerOne / Bugcrowd / Intigriti),
  and no published safe-harbor or scope statement.

program:
  exists: true
  type: email-disclosure
  formal_policy_published: false
  bug_bounty: false
  bounty_platform: null
  safe_harbor_published: false
  scope_published: false
  disclosure_page: https://runalphaloops.com/security
  contact_email: security@runalphaloop.com
  response_commitment: 24 hours
  verbatim: >-
    "Found a security issue? We appreciate responsible disclosure. Please email us with details
    and we'll respond within 24 hours. security@runalphaloop.com"

# DEFECT WORTH REPORTING TO THE PROVIDER — the published security contact uses the domain
# "runalphaloop.com" (SINGULAR "loop"), while the company, its site, its API and its MCP server
# all live on "runalphaloops.com" (PLURAL). The same singular-domain address appears as the
# general contact (hello@runalphaloop.com) in the site footer and in the OpenAPI info.contact
# block. If runalphaloop.com is not a domain AlphaLoops controls and routes, the advertised
# vulnerability-reporting channel does not reach them.
anomalies:
  - kind: contact-domain-mismatch
    severity: high
    detail: >-
      Security contact security@runalphaloop.com and general contact hello@runalphaloop.com use
      runalphaloop.com (singular), but every operational host is runalphaloops.com (plural).
    observed_at:
      - https://runalphaloops.com/security
      - https://runalphaloops.com/pricing
      - https://runalphaloops.com/openapi.json
    remediation: >-
      Confirm runalphaloop.com is owned and receiving mail, or correct the published addresses
      to @runalphaloops.com across the security page, site footer and OpenAPI info.contact.

security_txt:
  served: false
  probed:
    - url: https://runalphaloops.com/.well-known/security.txt
      http_status: 200
      result: miss
      note: SPA catch-all returns the marketing HTML shell for every path; not a security.txt.
    - url: https://api.runalphaloops.com/.well-known/security.txt
      http_status: 404
      result: miss
    - url: https://mcp-freight.runalphaloops.com/.well-known/security.txt
      http_status: 404
      result: miss

evidence:
  - url: https://runalphaloops.com/security
    http_status: 200
    kind: disclosure page
    keywords:
      - Report a Vulnerability
      - responsible disclosure
      - security@

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/alphaloops-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.