Bloom & Wild · Vulnerability Disclosure

Bloom Wild Vulnerability Disclosure

Vulnerability disclosure

Bloom & Wild Group publishes a machine-readable security contact under RFC 9116 at the canonical path on every group storefront (bloomandwild.com, bloomandwild.de, bloomon.nl, bloomon.be, bloomon.dk). It is a security contact, not a full disclosure programme — there is no published Policy URL, no safe-harbour statement, no scope definition, no bounty, and no `Expires` field.

Bloom & Wild runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyE-CommerceRetailFlowersGiftingDirect to ConsumerSubscriptionConsumer GoodsLogisticsUnited KingdomB Corp
Program: Hackerone

Disclosure Policy

Security Contact

Contact
mailto:security-tech@bloomandwild.com

Source

Vulnerability Disclosure

bloom--wild-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-07'
method: searched
probe: true
source: https://www.bloomandwild.com/.well-known/security.txt
description: >-
  Bloom & Wild Group publishes a machine-readable security contact under RFC 9116
  at the canonical path on every group storefront (bloomandwild.com,
  bloomandwild.de, bloomon.nl, bloomon.be, bloomon.dk). It is a security contact,
  not a full disclosure programme — there is no published Policy URL, no safe-harbour
  statement, no scope definition, no bounty, and no `Expires` field.
program:
  published: true
  kind: security-contact
  channel: security.txt
  policy_url: null
  safe_harbour: unstated
  scope: unstated
  bounty: false
contact:
- mailto:security-tech@bloomandwild.com
preferred_languages:
- en
- fr
- de
canonical: https://www.bloomandwild.com/.well-known/security.txt
hiring: https://www.bloomandwild.com/careers
gaps:
- field: Expires
  required_by: RFC 9116 §2.5.5
  present: false
  impact: >-
    Without Expires a consumer cannot tell whether the contact is still
    maintained; RFC 9116 makes this field REQUIRED.
- field: Policy
  required_by: RFC 9116 §2.5.7 (optional)
  present: false
  impact: >-
    No published disclosure policy, so a researcher has no stated scope, no
    disclosure timeline and no safe-harbour commitment.
- field: Encryption
  required_by: RFC 9116 §2.5.4 (optional)
  present: false
  impact: No published key for encrypting a report.
bug_bounty:
  present: false
  checked:
  - url: https://hackerone.com/bloomandwild
    status: 404
  - url: https://bugcrowd.com/bloomandwild
    status: 404
evidence:
- url: https://www.bloomandwild.com/.well-known/security.txt
  status: 200
  content_type: text/plain; charset=UTF-8
  fetched: '2026-08-07'
  file: well-known/bloom--wild-security.txt
- url: https://www.bloomandwild.de/.well-known/security.txt
  status: 200
  fetched: '2026-08-07'
- url: https://www.bloomon.nl/.well-known/security.txt
  status: 200
  fetched: '2026-08-07'
notes:
- >-
  https://www.bloomandwild.com/security and /responsible-disclosure both return
  HTTP 200, but so does every invalid path on this host — the storefront serves a
  single Angular SPA shell for everything. A rendering fetch of a nonsense-path
  control returns the same document, so neither URL is evidence of a disclosure
  page and neither is recorded as one.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bloom--wild-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.