Lang.ai · Vulnerability Disclosure

Langai Vulnerability Disclosure

Vulnerability disclosure

Lang.ai runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyArtificial IntelligenceMachine-LearningNatural Language ProcessingConversation IntelligenceCustomer-SupportText ClassificationAnalyticsCustomer Experience
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@lang.ai

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: probed
probe: true
status: contact-only
summary: >-
  Lang.ai publishes no vulnerability disclosure policy, responsible-disclosure page or
  bug bounty program, and serves no /.well-known/security.txt — every path on lang.ai
  301-redirects to the Capacity landing page. The only machine-readable security contact
  found is the RFC 8659 CAA iodef record in lang.ai DNS.
policy: []
contact:
- mailto:security@lang.ai
bug_bounty: null
security_txt: null
evidence:
- source: 'DNS CAA record for lang.ai'
  kind: caa-iodef
  value: '0 iodef "mailto:security@lang.ai"'
  note: >-
    RFC 8659 iodef is the address a CA reports certificate-issuance incidents to; it is a
    published security contact but not a disclosure policy.
- source: https://lang.ai/.well-known/security.txt
  kind: security.txt
  http_status: 301
  result: >-
    Redirects to https://capacity.com/lang/?company=lang.ai and returns the marketing
    page as HTML 200 — no security.txt is served.
- source: https://capacity.com/.well-known/security.txt
  kind: security.txt
  http_status: 404
- source: https://capacity.com/security/
  kind: security-page
  http_status: 200
  result: >-
    Describes encryption, compliance and access controls, but contains no responsible
    disclosure process, bug bounty, or security reporting address.
gaps:
- No /.well-known/security.txt on either lang.ai or capacity.com.
- No responsible-disclosure or vulnerability-disclosure policy page.
- No bug bounty program found on HackerOne, Bugcrowd or Intigriti.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/langai-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.