Kondukto · Vulnerability Disclosure

Kondukto Vulnerability Disclosure

Vulnerability disclosure

Kondukto publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyApplication SecurityASPMVulnerability ManagementDevSecOpsSecurity OrchestrationSASTDASTSCASoftware Composition AnalysisContainer SecuritySBOMSecurity TestingCI/CDSecurity
Program: security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@invicti.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://www.invicti.com/.well-known/security.txt
notes: >-
  kondukto.io serves Invicti's canonical RFC 9116 security.txt following the acquisition, so the
  security contact for the Kondukto/Invicti ASPM product is Invicti's product security team. The
  document is well-formed: it carries a Canonical URI, a Contact address, an unexpired Expires
  field, a PGP public key for encrypted reports, and a Preferred-Languages field.
contact:
- mailto:security@invicti.com
canonical: https://www.invicti.com/.well-known/security.txt
expires: '2029-01-16T11:00:00.000Z'
encryption: inline PGP public key block (see well-known/kondukto-security.txt)
preferred_languages: [en]
policy: []
policy_published: false
bug_bounty:
  program: null
  platform: null
  note: >-
    No public bug-bounty or coordinated-disclosure policy page was found for kondukto.io or
    invicti.com. The security.txt provides a Contact address but no Policy URI. Invicti's marketing
    pages mention bug-bounty and VDP programs only as training data for their risk-scoring model,
    not as a program they operate.
evidence:
- source: https://kondukto.io/.well-known/security.txt
  kind: security.txt
  status: 200
  note: 301 redirect to https://www.invicti.com/.well-known/security.txt
  file: well-known/kondukto-security.txt
- source: well-known/kondukto-security.txt
  kind: security.txt (harvested)
- source: https://docs.kondukto.io/.well-known/security.txt
  kind: security.txt
  status: 404
checked:
- url: https://www.invicti.com/security/
  status: 404
- url: https://www.invicti.com/compliance/
  status: 200
  note: compliance posture only, no disclosure policy
related:
  well_known: well-known/kondukto-well-known.yml
  trust_center: security/kondukto-trust-center.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kondukto-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.