backstitch · Vulnerability Disclosure

Backstitch Vulnerability Disclosure

Vulnerability disclosure

backstitch runs a coordinated vulnerability disclosure program on Hackerone.

CompanyContent CurationEmployee CommunicationsInternal CommunicationsTotal RewardsContent AggregationNewslettersWidgetsREST
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

backstitch-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: probed
source: >-
  /.well-known/security.txt probes across every backstitch host, plus a search of
  backstitch.io and the public bug-bounty platforms
program_found: false
security_txt:
  served: false
  probes:
  - {url: 'https://api.backstit.ch/.well-known/security.txt', status: 404}
  - {url: 'https://docs.backstit.ch/.well-known/security.txt', status: 404}
  - {url: 'https://www.backstitch.io/.well-known/security.txt', status: 404}
  - {url: 'https://backstitch.io/.well-known/security.txt', status: 404}
  - url: https://trust.backstitch.io/.well-known/security.txt
    status: 200
    accepted: false
    note: >-
      REJECTED as a false positive. trust.backstitch.io is a Vanta single-page
      app whose catch-all returns 200 with the same HTML shell for every path;
      the body is `<!doctype html>`, not an RFC 9116 document.
disclosure_page:
  url: null
  note: >-
    No /security, /security-policy, /vulnerability-disclosure or responsible-
    disclosure page was found on backstitch.io (https://www.backstitch.io/security
    -> 404). The site's only security destination is the Vanta trust center at
    https://trust.backstitch.io/, whose content is JS-rendered and whose data API
    is auth-gated, so no disclosure policy or security contact could be read
    anonymously.
bug_bounty:
  platform: null
  url: null
  note: No HackerOne, Bugcrowd or Intigriti program was found for backstitch.
contacts: []
note: >-
  No published vulnerability disclosure program was found. No `Security` pointer
  is emitted — an absence recorded is not a presence, and the `security_disclosure`
  check must not fire on this file.
checked: '2026-08-13'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/backstitch-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.