Kredivo · Vulnerability Disclosure

Kredivo Vulnerability Disclosure

Vulnerability disclosure

Kredivo runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyPaymentsBuy Now Pay LaterBNPLLendingConsumer CreditCheckoutFintechE-CommerceIndonesiaSoutheast AsiaFinancial-Services
Program: Hackerone

Disclosure Policy

Security Contact

Contact
evidenceThe published security policy page directs security inquiries to security@kredivo.com. This is a real, dedicated security address — the only documented route for reporting a vulnerability — but it is presented as a general security contact rather than as a disclosure intake channel.
Contact
other_contacts{"email" => "support@kredivo.com", "hours" => "Monday–Sunday, 08:00–20:00", "purpose" => "General consumer support"}{"email" => "hello@kredivo.com", "phone" => "021-2205-5677", "purpose" => "Company inquiries"}
Contact
security_emailsecurity@kredivo.com
Contact
sourcehttps://kredivo.com/security-policy/

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
source: https://kredivo.com/security-policy/
api: Kredivo
summary: |
  Kredivo publishes a human-readable security policy page with a dedicated security contact address,
  but no formal vulnerability disclosure program. The automated probe pass (probe-security-programs.py)
  returned no hit because there is no security.txt and no page matching the standard
  responsible-disclosure patterns; this file records what a manual search of the published security
  surface actually found on 2026-07-19.
program:
  formal_vdp: false
  bug_bounty: false
  safe_harbor:
    published: false
  scope:
    published: false
  disclosure_policy:
    published: false
  note: |
    No responsible-disclosure policy, no defined scope, no safe-harbor language, no coordinated
    disclosure timeline and no researcher acknowledgements. Kredivo is not listed on HackerOne,
    Bugcrowd or Intigriti as far as the public surface shows.
contact:
  security_email: security@kredivo.com
  source: https://kredivo.com/security-policy/
  evidence: |
    The published security policy page directs security inquiries to security@kredivo.com. This is a
    real, dedicated security address — the only documented route for reporting a vulnerability — but
    it is presented as a general security contact rather than as a disclosure intake channel.
  other_contacts:
  - purpose: General consumer support
    email: support@kredivo.com
    hours: Monday–Sunday, 08:00–20:00
  - purpose: Company inquiries
    email: hello@kredivo.com
    phone: 021-2205-5677
security_txt:
  published: false
  probed: '2026-07-19'
  hosts_probed:
  - https://kredivo.com/.well-known/security.txt
  - https://kredivo.com/security.txt
  - https://doc.kredivo.com/.well-known/security.txt
  - https://sandbox.kredivo.com/.well-known/security.txt
  - https://finaccel.co/.well-known/security.txt
  - https://kredivocorp.com/.well-known/security.txt
  result: 404 on every host
  note: |
    Publishing an RFC 9116 security.txt pointing at security@kredivo.com would be a near-zero-cost
    improvement — the contact already exists, it is simply not machine-discoverable.
published_security_page:
  url: https://kredivo.com/security-policy/
  probed_status: 200
  linked_from: kredivo.com footer ("Kebijakan Keamanan")
  controls_described:
  - Two-factor authentication
  - Encryption in transit and at rest
  - Secure storage and backups
  - Protection against DDoS and MITM attacks
  - Strict internal access controls
  referenced_documents:
  - name: Security, Privacy and Architecture (SPARC) Documentation
    description: |
      Referenced from the security policy page as covering security protocols, technical
      infrastructure and privacy practices. Not independently verified as publicly accessible.
  note: |
    The controls are described in prose only. No certification is named, no attestation report is
    offered and no trust center exists. See conformance/kredivo-conformance.yml.
gaps:
- No formal vulnerability disclosure policy or coordinated disclosure process.
- No bug bounty program.
- No safe-harbor commitment for good-faith researchers.
- No RFC 9116 security.txt, so the existing security contact is not machine-discoverable.
- No published response-time commitment for security reports.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kredivo-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.