HORIZON SHIELD · Vulnerability Disclosure

Horizonshield Dev Vulnerability Disclosure

Vulnerability disclosure

HORIZON SHIELD runs a coordinated vulnerability disclosure program on Hackerone.

ConstructionRenovationCost EstimationFair PricingConsumer ProtectionVerificationTransparency LedgerOpen DataMCPA2AAP2AgentsAgent-NativeJapan
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
source: https://gate.horizonshield.dev/.well-known/security.txt
docs:
- https://ledger.horizonshield.dev/.well-known/security.txt
- https://shield.the-horizons-innovation.com/verify-directory/
- https://ledger.horizonshield.dev/llms.txt
program: RFC 9116 security.txt on two service hosts (no bug bounty platform)
security_txt:
- host: gate.horizonshield.dev
  url: https://gate.horizonshield.dev/.well-known/security.txt
  status: 200
  file: well-known/horizonshield-dev-security.txt
  contact: mailto:contact@the-horizons-innovation.com
  policy: https://shield.the-horizons-innovation.com/verify-directory/
  canonical: https://gate.horizonshield.dev/.well-known/security.txt
  preferred_languages: [en, ja]
  expires: null
  scope_statement: 'This service publishes verdicts about other people''s servers. If a verdict here is wrong, that is a security problem, not a support ticket. Send the endpoint, what you measured, and from where. A report that contradicts our own measurement is the most useful kind, and it will be published either way.'
- host: ledger.horizonshield.dev
  url: https://ledger.horizonshield.dev/.well-known/security.txt
  status: 200
  file: well-known/horizonshield-dev-ledger-security.txt
  contact: mailto:thehorizon.nnovation@icloud.com
  policy: https://ledger.horizonshield.dev/llms.txt
  canonical: https://ledger.horizonshield.dev/.well-known/security.txt
  preferred_languages: [ja, en]
  expires: '2027-07-26T00:00:00.000Z'
  scope_statement: 'This ledger is read-only and unauthenticated by design. If you find a way to make a record''s bytes disagree with its published hash, or to make a verification recipe return a result that cannot be reproduced, that is the vulnerability we most want to hear about.'
absent_on:
- {host: mcp.horizonshield.dev, status: 404}
- {host: shield.the-horizons-innovation.com, status: 404}
- {host: horizonshield.dev, status: 0, note: does not resolve}
bug_bounty: null
disclosure_page: null
notes: >-
  Two RFC 9116 files with Contact and Policy lines and a stated scope of what counts as a vulnerability; the gate
  copy lacks the mandatory Expires field and its Policy target is the register page rather than a disclosure policy.
  No HackerOne / Bugcrowd / Intigriti programme and no dedicated disclosure page were found. The repository carries
  an ops/security_audit_20260913.md and a .gitleaks.toml, which suggest an internal practice but are not a public
  programme. The probe-security-programs.py script could not find these because it probes the registrable domain,
  which does not resolve.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/horizonshield-dev-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.