Clozd · Vulnerability Disclosure

Clozd Vulnerability Disclosure

Vulnerability disclosure

Clozd runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Win-Loss AnalysisCustomer FeedbackDecision IntelligenceSales IntelligenceMarket ResearchCompetitive IntelligenceVoice of CustomerRevenue IntelligenceSoftware-as-a-ServiceMCPagent-native
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@clozd.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: probed
probe: true
status: contact-only
policy: []
policy_published: false
bug_bounty:
  program: none-found
  platforms_checked:
  - HackerOne
  - Bugcrowd
  - Intigriti
contact:
- security@clozd.com
security_txt:
  present: false
  paths_checked:
  - https://www.clozd.com/.well-known/security.txt
  - https://clozd.com/.well-known/security.txt
  - https://app.clozd.com/.well-known/security.txt
  - https://mcp.clozd.com/.well-known/security.txt
  note: >-
    404 on the marketing hosts; the app and MCP hosts return an HTML SPA shell with status 200, which is
    not a security.txt.
disclosure_pages_checked:
- url: https://www.clozd.com/security
  http_status: 404
- url: https://www.clozd.com/security/responsible-disclosure
  http_status: 404
- url: https://www.clozd.com/responsible-disclosure
  http_status: 404
- url: https://www.clozd.com/vulnerability-disclosure
  http_status: 404
- url: https://www.clozd.com/trust
  http_status: 404
- url: https://www.clozd.com/compliance
  http_status: 404
evidence:
- source: DNS CAA record for clozd.com
  kind: dns-iodef
  value: 0 iodef "mailto:security@clozd.com"
  note: >-
    The only machine-readable security contact Clozd publishes. RFC 8659 iodef is a CA-incident reporting
    address, not a vulnerability disclosure policy, but it is a real, verifiable, published security inbox.
- source: https://trust.clozd.com
  kind: trust-center
  http_status: 200
  note: Vanta trust center exists; no public disclosure policy is linked from clozd.com.
assessment: >-
  Clozd publishes no vulnerability disclosure policy, no security.txt and no bug bounty program. A security
  contact address is discoverable only from the DNS CAA iodef record. This artifact records the contact and
  the verified absence of a policy — it is deliberately NOT wired to a `Security` pointer in apis.yml,
  because no security or disclosure policy page exists to point at.
recommendation: >-
  Publish /.well-known/security.txt (RFC 9116) on www.clozd.com and app.clozd.com with Contact,
  Policy, Preferred-Languages and Expires, and add a responsible-disclosure page linked from the trust
  center.
x-evidence:
  fetched: '2026-08-04'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/clozd-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.