Graphite · Vulnerability Disclosure
Graphite Com Vulnerability Disclosure
Vulnerability disclosure
Graphite runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
Code ReviewStacked PRsMerge QueueAI Code ReviewDeveloper ToolsGitHub
Program: Hackerone
Disclosure Policy
Security Contact
Contact
security@graphite.com
Source
Vulnerability Disclosure
generated: '2026-08-04'
method: searched
probe: true
probe_result: >-
probe-security-programs.py returned vdp=none — Graphite serves no
/.well-known/security.txt (404 on graphite.com and api.graphite.dev, probed
2026-08-04) and has no /security, /trust or /responsible-disclosure page.
What follows was found by reading the published documentation instead.
policy:
- https://graphite.com/docs/privacy-and-security
- https://trust.cursor.com
contact:
- security@graphite.com
security_txt:
present: false
probed:
- {url: 'https://graphite.com/.well-known/security.txt', http_status: 404}
- {url: 'https://graphite.com/security.txt', http_status: 404}
- {url: 'https://api.graphite.dev/.well-known/security.txt', http_status: 404}
bug_bounty:
present: false
platforms: []
note: >-
No HackerOne, Bugcrowd, or Intigriti program was found for graphite.com. The
trust center is operated by the parent company (trust.cursor.com); any bounty
program would live there and could not be confirmed anonymously — the page is
a JavaScript application that serves only a title to an unauthenticated
fetch.
security_practices:
soc2_type_ii: true
continuous_penetration_testing: true
encryption_in_transit: true
encryption_at_rest: true
token_encryption: aes-256-cbc with a secret held in AWS Secrets Manager
layered_key_separation: >-
Database contents are additionally encrypted with a key stored in a separate
service, so a database compromise alone does not yield GitHub API tokens.
ai_data_handling: >-
AI features are opt-in and do not store or train on customer data; AI
Summarize is PR-by-PR opt-in and runs on Anthropic's API under terms that
exclude customer source code from training sets.
code_indexing: >-
Opt-in, time-limited code indexing service; documented separately at
/docs/code-indexing-security.
source: https://graphite.com/docs/privacy-and-security
evidence:
- source: https://graphite.com/docs/privacy-and-security
kind: documentation
quote: >-
"If you have more questions about this feature, don't hesitate to shoot us a
message on Slack or email security@graphite.com."
- source: https://graphite.com/docs/privacy-and-security
kind: documentation
quote: >-
"We are SOC 2 Type II compliant... We also continuously pen test."
gaps:
- No RFC 9116 /.well-known/security.txt published on any Graphite host.
- No dedicated responsible-disclosure or vulnerability-reporting page.
- No stated response-time or safe-harbour commitment for reporters.
x-evidence:
fetched: '2026-08-04'
urls:
- {url: 'https://graphite-58cc94ce.mintlify.dev/docs/privacy-and-security.md', http_status: 200}
- {url: 'https://trust.cursor.com', http_status: 200, content_type: text/html}
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/graphite-com-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.