First Street · Vulnerability Disclosure

First Street Vulnerability Disclosure

Vulnerability disclosure

First Street publishes a complete, well-formed vulnerability disclosure policy inside its API documentation — reporting instructions, focus areas, an explicit in-scope and out-of-scope list, researcher conduct expectations and a safe-harbour clause. What it does not do is make that policy machine-discoverable: there is no /.well-known/security.txt on any of the nine hosts probed.

First Street runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

ClimateRisk ManagementEnvironmentModelingGeospatialInsuranceReal EstateDataGraphQLMapping
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
security@firststreet.org

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-10'
method: searched
probe: true
source: https://docs.firststreet.org/api/security
description: >-
  First Street publishes a complete, well-formed vulnerability disclosure policy inside
  its API documentation — reporting instructions, focus areas, an explicit in-scope and
  out-of-scope list, researcher conduct expectations and a safe-harbour clause. What it
  does not do is make that policy machine-discoverable: there is no
  /.well-known/security.txt on any of the nine hosts probed.
policy:
  - https://docs.firststreet.org/api/security
  - https://firststreet.org/security
contact:
  - security@firststreet.org
safe_harbor: true
safe_harbor_text: >-
  "Any activities conducted in a manner consistent with this policy will be considered
  authorized conduct and we will not initiate legal action against you. If legal action is
  initiated by a third party against you in connection with activities conducted under
  this policy, we will take steps to make it known that your actions were conducted in
  compliance with this policy."
bug_bounty: false
bug_bounty_note: No HackerOne, Bugcrowd or Intigriti program was found; reporting is direct to security@firststreet.org.
report_should_include:
  - A summary of the issue and potential impact
  - A breakdown of the steps to replicate the issue
  - Details of the environment you are using
  - If available, any proof-of-concept code to exploit the vulnerability
focus_areas:
  - Authentication bypass and privilege escalation
  - Exposure of personally identifiable information (PII)
  - Access to data outside of the authenticated user
  - SQL injection and remote command execution
in_scope:
  - https://firststreet.org
  - https://api.firststreet.org
out_of_scope:
  - Automated scanning of any kind
  - Social engineering of any kind
  - Denial of Service attacks of any kind
  - Attacks requiring physical access to the victim's computer
  - Theoretical attacks without proof of exploitability
  - Man-in-the-middle attacks
  - Clickjacking on pages with no sensitive actions
  - High-privilege users sabotaging their own workspace
  - Logic bugs bypassing free-account limits
  - Missing best practices in CSP, email DNS records or cookies
security_txt:
  served: false
  probed_hosts: 9
  artifact: well-known/first-street-well-known.yml
  gap: >-
    A three-line /.well-known/security.txt on firststreet.org pointing Policy: at the
    docs page and Contact: at security@firststreet.org would make an already-good policy
    discoverable by a machine. It is the cheapest fix in this record.
evidence:
  - {source: 'https://docs.firststreet.org/api/security', kind: disclosure policy, http_status: 200, keywords: [reporting vulnerabilities, safe harbor, in scope, out-of-scope, 'security@firststreet.org']}
  - {source: 'https://firststreet.org/security', kind: security page, http_status: 200, keywords: ['soc 2', 'penetration test', vulnerability]}
  - {source: 'https://github.com/FirstStreet/api/blob/HEAD/README.md', kind: repo policy, quote: 'Please report vulnerabilities to security@firststreet.org.'}
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/first-street-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.