First Street · Vulnerability Disclosure
First Street Vulnerability Disclosure
Vulnerability disclosure
First Street publishes a complete, well-formed vulnerability disclosure policy inside its API documentation — reporting instructions, focus areas, an explicit in-scope and out-of-scope list, researcher conduct expectations and a safe-harbour clause. What it does not do is make that policy machine-discoverable: there is no /.well-known/security.txt on any of the nine hosts probed.
First Street runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
ClimateRisk ManagementEnvironmentModelingGeospatialInsuranceReal EstateDataGraphQLMapping
Program: Hackerone
Disclosure Policy
Security Contact
Contact
security@firststreet.org
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.