AngelList · Vulnerability Disclosure
Angellist Vulnerability Disclosure
Vulnerability disclosure
AngelList runs a coordinated vulnerability disclosure program on Hackerone.
DocumentsFundsInvestingJobStartupsTransactionVenture Capital
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-02'
method: probed
probe: true
published: false
supersedes:
generated: '2026-07-11'
method: searched
source: https://www.angellist.com/vulnerability-disclosure
verdict: false-positive
reason: >-
That URL returns HTTP 200 with the www.angellist.com catch-all SPA shell —
the same ~95.9KB body returned for a negative-control path that cannot
exist. The word "vulnerability" the earlier probe matched came from the
shell's own markup, not from a disclosure policy. Corrected 2026-09-02.
note: >-
AngelList publishes no public vulnerability-disclosure channel: no
security.txt on any host it controls, no responsible-disclosure page, and no
bug bounty on HackerOne, Bugcrowd or Intigriti reachable from its site. What
it does publish is a trust center listing a Vulnerability and Patch Management
Policy and offering penetration-test reports on request — captured separately
in security/angellist-trust-center.yml. This file records the absence with
evidence so it is a true zero rather than a false credit.
policy: []
contact: []
security_txt:
published: false
hosts_probed:
- {host: www.angellist.com, http_status: 200, verdict: soft-404 catch-all shell, bytes: 95977}
- {host: docs.angellist.com, http_status: 200, verdict: login shell, bytes: 31322}
- {host: support.angellist.com, http_status: 404}
- {host: portal-api.angellist.com, http_status: 404}
- {host: venture.angellist.com, http_status: 404}
- {host: auth.angellist.com, http_status: 404}
related_but_not_angellist:
host: wellfound.com
path: /.well-known/security.txt
http_status: 200
content_type: text/plain
contact: mailto:security@wellfound.com
file: ../well-known/wellfound-security.txt
note: >-
Wellfound, the former AngelList Talent business, does serve a valid RFC 9116
security.txt. It is saved for the record but it is Wellfound's disclosure
channel on Wellfound's domain, not AngelList Venture's, so it earns AngelList
no SecurityTxt or Security pointer.
evidence:
- url: https://www.angellist.com/vulnerability-disclosure
http_status: 200
bytes: 95932
verdict: soft-404 (catch-all shell)
- url: https://www.angellist.com/responsible-disclosure
http_status: 200
bytes: 95971
verdict: soft-404 (catch-all shell)
- url: https://www.angellist.com/legal/security
http_status: 200
bytes: 95914
verdict: soft-404 (catch-all shell)
- url: https://www.angellist.com/apis-io-negative-control-7f3ab91c
http_status: 200
bytes: 95950
verdict: negative control — proves the three results above are the same shell
- url: https://security.angellist.com/
http_status: <no response>
verdict: host does not resolve to a served endpoint
- url: https://trust-portal.angellist.com/
http_status: 200
verdict: >-
real trust center; documents a Vulnerability and Patch Management Policy but
publishes no reporting address or disclosure process
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/angellist-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.