Clear Street · Vulnerability Disclosure

Clear Street Vulnerability Disclosure

Vulnerability disclosure

Clear Street runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyFinancial ServicesCapital MarketsPrime BrokerageTradingBrokerageClearingMarket DataFintechInvesting
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@clearstreet.io

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-02'
method: searched
probe: true
probe_result: none
probe_note: >
  probe-security-programs.py returned vdp=none — there is no /.well-known/security.txt on any
  Clear Street host, and none of the conventional disclosure paths (/security/responsible-disclosure,
  /responsible-disclosure, /vulnerability-disclosure, /security) exist at the apex. The security
  page lives at /legal/security on the corporate site, which the mechanical probe does not reach.
status: contact-only
status_note: >
  Clear Street publishes a security CONTACT and a security program page, but NOT a formal
  vulnerability disclosure policy: there is no stated scope, no safe-harbour language, no
  response-time commitment, and no bug bounty program. Recorded honestly as contact-only.
policy: []
policy_url: https://www.clearstreet.io/legal/security
contact:
- security@clearstreet.io
security_txt:
  published: false
  probed_hosts: [clearstreet.io, www.clearstreet.io, clearstreet.com, www.clearstreet.com,
    api.clearstreet.com, api.clearstreet.io, docs.clearstreet.com, docs.clearstreet.io,
    auth.clearstreet.io]
  http_status: 404
  rfc: RFC 9116
  gap: >
    Adding /.well-known/security.txt with Contact: mailto:security@clearstreet.io and a Policy:
    URL would be a one-file fix that makes the existing contact machine-discoverable.
bug_bounty:
  published: false
  checked: [HackerOne, Bugcrowd, Intigriti, YesWeHack]
sdk_security_policy:
  present: true
  note: >
    Every first-party SDK, CLI and the skills repository ships a SECURITY.md and a `security`
    GitHub Actions workflow, so per-repository reporting guidance does exist even though the
    corporate site carries no VDP.
  repos: [clear-street-python, clear-street-typescript, clear-street-go, clear-street-java,
    clear-street-cli, studio-sdk-python, studio-sdk-node, studio-sdk-java, clearstreet-skills]
evidence:
- {source: 'https://www.clearstreet.io/legal/security', kind: security-page, http_status: 200,
   keywords: ['security@clearstreet.io', 'security controls', 'trust center']}
- {source: 'https://www.clearstreet.io/legal/clear-street-trust-center', kind: trust-center,
   http_status: 200, keywords: ['vulnerability management', 'incident response']}
- {source: 'https://github.com/clear-street/clearstreet-skills/blob/main/SECURITY.md',
   kind: repo-security-policy}
x-evidence:
  fetched: '2026-08-02'
  probes_missed:
  - {url: 'https://www.clearstreet.io/.well-known/security.txt', http_status: 404}
  - {url: 'https://www.clearstreet.com/.well-known/security.txt', http_status: 404}
  - {url: 'https://auth.clearstreet.io/.well-known/security.txt', http_status: 404}