Langdock · Vulnerability Disclosure

Langdock Vulnerability Disclosure

Vulnerability disclosure

Langdock publishes a Vulnerability Disclosure Policy with a scoped bug bounty program, explicit safe-harbor terms, and committed response timelines. There is no /.well-known/security.txt on any Langdock host (all probed hosts returned 404), so the policy page and the security@ mailbox are the disclosure surface.

Langdock publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyArtificial IntelligenceEnterprise AILLMAgentsMCPWorkflowsKnowledge-ManagementGermanyEurope
Program:

Disclosure Policy

Policy

Security Contact

Contact
security@langdock.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: false
source: https://www.langdock.com/vulnerability-disclosure-policy
description: >-
  Langdock publishes a Vulnerability Disclosure Policy with a scoped bug bounty
  program, explicit safe-harbor terms, and committed response timelines. There is
  no /.well-known/security.txt on any Langdock host (all probed hosts returned 404),
  so the policy page and the security@ mailbox are the disclosure surface.
policy:
- https://www.langdock.com/vulnerability-disclosure-policy
contact:
- security@langdock.com
bug_bounty:
  program: Langdock Vulnerability Disclosure Policy (self-hosted, not on a platform)
  platform: null
  monetary_rewards: true
  reward_categories:
  - Remote Code Execution (RCE)
  - Cross Site Scripting (XSS)
  - Server-Side Request Forgery (SSRF)
  - SQL Injection (SQLi)
  - Insecure Direct Object References (IDOR)
  - Authentication bypass
  - Privilege escalation
  - Severe information or PII disclosure
  non_monetary: Other valid in-scope reports may receive mentions or Langdock swag.
  excluded_from_reward: >-
    Low-quality, low-impact, or informational issues (missing security headers,
    weak TLS ciphers, version disclosures). Duplicates — only the first valid
    report is eligible. Bounty amounts are not negotiated.
scope:
  in_scope:
  - Langdock Platform (app.langdock.com)
  out_of_scope:
  - Marketing website (www.langdock.com)
  - Mobile applications
  - Third-party dependencies or systems owned by other entities
  - Physical security, social engineering, phishing, spam, brute-force attacks
  - Denial-of-Service (DoS), distributed DoS (DDoS), or resource exhaustion attacks
  - Automated scanning or fuzzing that degrades service
safe_harbor:
  offered: true
  terms: >-
    Researchers acting in good faith, following the policy, and avoiding privacy
    violations, service disruption, or data destruction are protected from legal
    action by Langdock. All information provided is kept confidential.
response_timelines:
  acknowledgement: within 3 business days
  progress_updates: at least every 10 business days until resolution
  post_resolution: >-
    Upon validation and mitigation, Langdock alerts affected customers and may
    issue a security advisory.
reporting_requirements:
- Detailed summary and attack surface (URL and parameters)
- Potential weakness and tools used
- Proof of concept with clear, reproducible steps
- Severity level (CVSS 3.1 or low/medium/high/critical)
- Any plans for public disclosure
security_txt:
  present: false
  probed:
  - path: https://www.langdock.com/.well-known/security.txt
    status: 404
  - path: https://api.langdock.com/.well-known/security.txt
    status: 404
  - path: https://docs.langdock.com/.well-known/security.txt
    status: 404
evidence:
- source: https://www.langdock.com/vulnerability-disclosure-policy
  kind: disclosure-policy-page
  keywords:
  - bug bounty
  - responsible disclosure
  - safe harbor
  - security@langdock.com
related:
  trust_center: security/langdock-trust-center.yml
  security_overview: https://www.langdock.com/security

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/langdock-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.