Clear Street · Vulnerability Disclosure

Clear Street Vulnerability Disclosure

Vulnerability disclosure

Clear Street runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyFinancial-ServicesCapital MarketsPrime BrokerageTradingBrokerageClearingMarket DataFintechInvesting
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@clearstreet.io

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-02'
method: searched
probe: true
probe_result: none
probe_note: >
  probe-security-programs.py returned vdp=none — there is no /.well-known/security.txt on any
  Clear Street host, and none of the conventional disclosure paths (/security/responsible-disclosure,
  /responsible-disclosure, /vulnerability-disclosure, /security) exist at the apex. The security
  page lives at /legal/security on the corporate site, which the mechanical probe does not reach.
status: contact-only
status_note: >
  Clear Street publishes a security CONTACT and a security program page, but NOT a formal
  vulnerability disclosure policy: there is no stated scope, no safe-harbour language, no
  response-time commitment, and no bug bounty program. Recorded honestly as contact-only.
policy: []
policy_url: https://www.clearstreet.io/legal/security
contact:
- security@clearstreet.io
security_txt:
  published: false
  probed_hosts: [clearstreet.io, www.clearstreet.io, clearstreet.com, www.clearstreet.com,
    api.clearstreet.com, api.clearstreet.io, docs.clearstreet.com, docs.clearstreet.io,
    auth.clearstreet.io]
  http_status: 404
  rfc: RFC 9116
  gap: >
    Adding /.well-known/security.txt with Contact: mailto:security@clearstreet.io and a Policy:
    URL would be a one-file fix that makes the existing contact machine-discoverable.
bug_bounty:
  published: false
  checked: [HackerOne, Bugcrowd, Intigriti, YesWeHack]
sdk_security_policy:
  present: true
  note: >
    Every first-party SDK, CLI and the skills repository ships a SECURITY.md and a `security`
    GitHub Actions workflow, so per-repository reporting guidance does exist even though the
    corporate site carries no VDP.
  repos: [clear-street-python, clear-street-typescript, clear-street-go, clear-street-java,
    clear-street-cli, studio-sdk-python, studio-sdk-node, studio-sdk-java, clearstreet-skills]
evidence:
- {source: 'https://www.clearstreet.io/legal/security', kind: security-page, http_status: 200,
   keywords: ['security@clearstreet.io', 'security controls', 'trust center']}
- {source: 'https://www.clearstreet.io/legal/clear-street-trust-center', kind: trust-center,
   http_status: 200, keywords: ['vulnerability management', 'incident response']}
- {source: 'https://github.com/clear-street/clearstreet-skills/blob/main/SECURITY.md',
   kind: repo-security-policy}
x-evidence:
  fetched: '2026-08-02'
  probes_missed:
  - {url: 'https://www.clearstreet.io/.well-known/security.txt', http_status: 404}
  - {url: 'https://www.clearstreet.com/.well-known/security.txt', http_status: 404}
  - {url: 'https://auth.clearstreet.io/.well-known/security.txt', http_status: 404}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/clear-street-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.