Hidden Road · Vulnerability Disclosure

Hidden Road Vulnerability Disclosure

Vulnerability disclosure

Hidden Road runs a coordinated vulnerability disclosure program on Bugcrowd.

CompanyFinancial ServicesPrime BrokerageClearingDigital AssetsForeign ExchangeCapital MarketsTradingInstitutional FinanceCollateral ManagementRisk ManagementRegulated
Program: Bugcrowd

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

hidden-road-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-22'
method: probed
source: >-
  Live probes of hiddenroad.com/.well-known/security.txt, hiddenroad.com's former
  responsible-disclosure page, and ripple.com/legal/bug-bounty/
published: false
summary: >-
  Hidden Road has NO reachable vulnerability disclosure surface of its own. It formerly
  published a "Responsible Disclosure of Information" page at
  hiddenroad.com/disclosures/responsible-disclosure-of-information/ (present in the Wayback
  index); every path on hiddenroad.com now 301s to a single Ripple marketing page, so that
  policy is gone. No security.txt is served on any Hidden Road host. Ripple runs a bug bounty
  on Bugcrowd, but the published scope names only Ripple Payments, the XRP Ledger, RLUSD and
  the XRPL EVM Sidechain — Hidden Road, Ripple Prime and hiddenroad.com are NOT in scope. A
  researcher who finds a flaw in api.hiddenroad.com today has no published channel.
security_txt:
  served: false
  probes:
  - url: https://hiddenroad.com/.well-known/security.txt
    status: 301
    redirects_to: https://ripple.com/products/prime-brokerage/
    note: Soft-404 — the redirect target is a marketing page, not a policy.
  - url: https://auth.hiddenroad.com/.well-known/security.txt
    status: 404
  - url: https://api.hiddenroad.com/.well-known/security.txt
    status: 403
    note: API Gateway "Missing Authentication Token" — path not routed.
  - url: https://ripple.com/.well-known/security.txt
    status: 404
disclosure_pages:
- url: https://hiddenroad.com/disclosures/responsible-disclosure-of-information/
  status: 301
  live: false
  note: >-
    Existed on the pre-acquisition WordPress site (Wayback CDX). Now blanket-redirected to
    https://ripple.com/products/prime-brokerage/ along with every other hiddenroad.com path,
    including the firm's regulatory disclosures.
- url: https://ripple.com/legal/bug-bounty/
  status: 200
  live: true
  platform: Bugcrowd (private, invitation-only)
  contact: bugs@ripple.com
  covers_hidden_road: false
  note: >-
    Scope as published lists Ripple Payment Products, XRP Ledger (rippled, Clio, xrpl.js,
    xrpl-py, xrpl4j), RLUSD contracts and the XRPL EVM Sidechain. Prime brokerage is absent.
remediation: >-
  Serve an RFC 9116 security.txt on hiddenroad.com and api.hiddenroad.com, or add Ripple Prime
  and *.hiddenroad.com to the published Bugcrowd scope. Restoring the responsible-disclosure
  page at a stable URL would be the smallest fix.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hidden-road-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.