Copper.co · Vulnerability Disclosure

Copper Co Vulnerability Disclosure

Vulnerability disclosure

Copper.co runs a coordinated vulnerability disclosure program on Hackerone.

CompanyDigital Asset CustodyCryptocurrencyFinancial ServicesInstitutional FinancePrime BrokerageCollateral ManagementLendingSettlementStakingBlockchainTreasury Management
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: probed
probe: true
found: false
source: live probes on 2026-08-04
summary: >-
  NEGATIVE RESULT, recorded so the search is not repeated. Copper publishes no
  vulnerability disclosure programme that could be found from the public surface: no
  RFC 9116 security.txt on any host, no responsible-disclosure or vulnerability-disclosure
  page, no bug bounty programme on HackerOne, Bugcrowd or Intigriti, and no security@
  reporting address. The /en/security page describes security posture and certifications
  but contains no reporting channel for external researchers.
  Because nothing was verified, NO `Security` or `VulnerabilityDisclosure` pointer is
  wired into apis.yml — this file documents the absence only.
policy: []
contact: []
bug_bounty:
  hackerone: false
  bugcrowd: false
  intigriti: false
  self_hosted: false
security_txt:
  published: false
  hosts_checked:
  - copper.co
  - www.copper.co
  - api.copper.co
  - developer.copper.co
  note: >-
    www.copper.co returns 200 for /.well-known/security.txt but the body is the marketing
    SPA HTML shell, not a security.txt — rejected as a catch-all false positive.
pages_checked:
- url: https://copper.co/en/security
  status: 200
  disclosure_program_found: false
  note: Security posture and certifications only; no reporting channel or disclosure policy.
- url: https://copper.co/security
  status: 200
  note: Redirects to /en/security.
probe_output: 'probe-security-programs.py copper-co -> vdp=none'
related:
  trust_center: security/copper-co-trust-center.yml
  contact_general: hello@copper.co
recommendation: >-
  Publishing /.well-known/security.txt with a Policy and Contact, and a responsible
  disclosure page, is the cheapest operational-transparency win available to Copper —
  and a conspicuous gap for a custodian holding institutional digital assets.