Clear Street · Vulnerability Disclosure
Clear Street Vulnerability Disclosure
Vulnerability disclosure
Clear Street runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
CompanyFinancial-ServicesCapital MarketsPrime BrokerageTradingBrokerageClearingMarket DataFintechInvesting
Program: Hackerone
Disclosure Policy
Security Contact
Contact
security@clearstreet.io
Source
Vulnerability Disclosure
generated: '2026-08-02'
method: searched
probe: true
probe_result: none
probe_note: >
probe-security-programs.py returned vdp=none — there is no /.well-known/security.txt on any
Clear Street host, and none of the conventional disclosure paths (/security/responsible-disclosure,
/responsible-disclosure, /vulnerability-disclosure, /security) exist at the apex. The security
page lives at /legal/security on the corporate site, which the mechanical probe does not reach.
status: contact-only
status_note: >
Clear Street publishes a security CONTACT and a security program page, but NOT a formal
vulnerability disclosure policy: there is no stated scope, no safe-harbour language, no
response-time commitment, and no bug bounty program. Recorded honestly as contact-only.
policy: []
policy_url: https://www.clearstreet.io/legal/security
contact:
- security@clearstreet.io
security_txt:
published: false
probed_hosts: [clearstreet.io, www.clearstreet.io, clearstreet.com, www.clearstreet.com,
api.clearstreet.com, api.clearstreet.io, docs.clearstreet.com, docs.clearstreet.io,
auth.clearstreet.io]
http_status: 404
rfc: RFC 9116
gap: >
Adding /.well-known/security.txt with Contact: mailto:security@clearstreet.io and a Policy:
URL would be a one-file fix that makes the existing contact machine-discoverable.
bug_bounty:
published: false
checked: [HackerOne, Bugcrowd, Intigriti, YesWeHack]
sdk_security_policy:
present: true
note: >
Every first-party SDK, CLI and the skills repository ships a SECURITY.md and a `security`
GitHub Actions workflow, so per-repository reporting guidance does exist even though the
corporate site carries no VDP.
repos: [clear-street-python, clear-street-typescript, clear-street-go, clear-street-java,
clear-street-cli, studio-sdk-python, studio-sdk-node, studio-sdk-java, clearstreet-skills]
evidence:
- {source: 'https://www.clearstreet.io/legal/security', kind: security-page, http_status: 200,
keywords: ['security@clearstreet.io', 'security controls', 'trust center']}
- {source: 'https://www.clearstreet.io/legal/clear-street-trust-center', kind: trust-center,
http_status: 200, keywords: ['vulnerability management', 'incident response']}
- {source: 'https://github.com/clear-street/clearstreet-skills/blob/main/SECURITY.md',
kind: repo-security-policy}
x-evidence:
fetched: '2026-08-02'
probes_missed:
- {url: 'https://www.clearstreet.io/.well-known/security.txt', http_status: 404}
- {url: 'https://www.clearstreet.com/.well-known/security.txt', http_status: 404}
- {url: 'https://auth.clearstreet.io/.well-known/security.txt', http_status: 404}
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/clear-street-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.