Cledara · Vulnerability Disclosure

Cledara Vulnerability Disclosure

Vulnerability disclosure

Cledara runs a coordinated vulnerability disclosure program on Hackerone.

FinanceSaaS ManagementSoftware SpendingSpend ManagementSubscription ManagementVirtual CardsExpense ManagementFinOpsMCPMarket Data
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-05'
method: probed
source: >-
  /.well-known/security.txt probed on ten Cledara hosts (see well-known/cledara-well-known.yml),
  plus https://www.cledara.com/security and https://trust.cledara.com/
provider: Cledara
providerId: cledara
present: false
security_txt:
  served: false
  hosts_probed:
    - www.cledara.com
    - cledara.com
    - api.cledara.com
    - api-docs.cledara.com
    - app.cledara.com
    - help.cledara.com
    - announcements.cledara.com
    - data.cledara.com
    - statuspage.cledara.com
    - trust.cledara.com
  note: >-
    404 on every host except statuspage.cledara.com and trust.cledara.com, which return a
    single-page-app HTML shell with a 200 for every path — not a security.txt.
disclosure_policy:
  published: false
  url: null
bug_bounty:
  program: null
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program was found for Cledara.
security_contact:
  published: false
  note: >-
    Cledara's security page describes penetration testing and tokenization but names no
    security contact address, no responsible-disclosure policy and no PGP key. The only
    published route for a reporter is the general help centre.
finding: >-
  HONEST ABSENCE. Cledara is an FCA-registered EMD agent issuing Mastercard and Visa cards
  and holds SOC 2 Type II, yet publishes no coordinated vulnerability disclosure route at
  all. This is a gap the provider can close cheaply with an RFC 9116 security.txt at
  https://www.cledara.com/.well-known/security.txt.
maintainers:
  - FN: Kin Lane
    email: kinlane@gmail.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cledara-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.