Hnry · Vulnerability Disclosure

Hnry Vulnerability Disclosure

Vulnerability disclosure

Hnry runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

AccountingTaxPaymentsInvoicingExpense ManagementFinancial ServicesSole TradersPayrollFintechNew ZealandAustraliaUnited Kingdom
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy

Security Contact

Contact
channelemail
Contact
emailsecurity@hnry.com

Source

Vulnerability Disclosure

hnry-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-22'
method: searched
source: https://app.hnry.io/security.txt
program: true
security_txt:
  url: https://app.hnry.io/security.txt
  status: 200
  content_type: text/plain; charset=utf-8
  file: ../well-known/hnry-security.txt
  rfc9116_path: false
  rfc9116_note: >-
    RFC 9116 requires the file at /.well-known/security.txt. Hnry serves it from the web root
    instead — /.well-known/security.txt returns 404 on every Hnry host, while /security.txt
    returns 200 on app.hnry.io and uk.hnry.com, and 301s to those from hnry.co.nz, hnry.com.au
    and hnry.co.uk. Automated scanners that only check the well-known path will miss it. Hnry
    signposts the file in prose on https://hnry.co.nz/privacy-and-security/: "If you're a
    security researcher, see app.hnry.io/security.txt for how to communicate directly with our
    security team."
  fields:
    contact: mailto:security@hnry.com
    expires: '2029-12-31T13:00:00.000Z'
    canonical: https://app.hnry.io/security.txt
    policy: https://hnry.notion.site/hnry-responsible-disclosure-guidelines
  missing_fields:
  - Encryption
  - Acknowledgments
  - Preferred-Languages
  - Hiring
  - CSAF
contact:
  email: security@hnry.com
  channel: email
policy:
  url: https://hnry.notion.site/hnry-responsible-disclosure-guidelines
  status: 200
  readable: false
  finding: >-
    DEAD POLICY LINK IN PRACTICE. The Policy: URL in Hnry's own security.txt resolves to a Notion
    page that returns HTTP 200 but is not publicly shared — Notion's getPublicPageData reports
    publicAccessRole "none", so the page renders the generic Notion marketing shell to anyone
    outside the Hnry workspace. A security researcher following the pointer Hnry publishes cannot
    read the responsible disclosure guidelines, the safe-harbour terms, or the scope. Fixable by
    Hnry in one click (share the Notion page to the web).
bug_bounty:
  program: false
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program was found for Hnry.
disclosure_pages:
- url: https://hnry.co.nz/privacy-and-security/
  status: 200
  note: Names the security.txt location and the security team channel.
- url: https://hnry.co.nz/security/
  status: 404
- url: https://hnry.co.nz/responsible-disclosure/
  status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hnry-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.