Bidmachine Io Vulnerability Disclosure
BidMachine publishes a Responsible Vulnerability Disclosure Policy as a web page (linked from the site footer as "Report an IT Vulnerability"). Scope: "all BidMachine-owned systems, services, APIs, and applications operating under the bidmachine.io domain and any associated subdomains". Reports go to the security mailbox; the policy sets researcher rules (no exploitation, no disruption, no public disclosure before remediation) and commits to prompt, transparent response. No bug bounty platform (HackerOne/Bugcrowd/Intigriti) and no RFC 9116 security.txt on any host. The page lives on www.bidmachine.com; https://bidmachine.io/responsible-vulnerability-disclosure-policy 301s to it.
BidMachine runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.