LayerX · Vulnerability Disclosure

Layerx Vulnerability Disclosure

Vulnerability disclosure

LayerX runs a coordinated vulnerability disclosure program on Hackerone.

CompanyJapanBack OfficeExpense ManagementInvoicingAccounts PayableWorkflowApprovalsAccountingPayrollAttendanceCorporate CardsArtificial IntelligenceAI AgentsDocument ProcessingSaaSEnterprise SoftwareFintech
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

layerx-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-23'
method: searched
source: https://layerx.co.jp/security_policy/
api: n/a
program:
  published: true
  type: security-contact
  contact_email: security@layerx.co.jp
  contact_page: https://layerx.co.jp/security_policy/
  http_status: 200
  probed: '2026-08-23'
  note: >-
    LayerX publishes a named security contact for vulnerability reports and
    security-related enquiries on its corporate 情報セキュリティ基本方針 page. It is a
    contact, not a program: there is no published disclosure policy, no coordinated
    disclosure timeline, no safe-harbour statement and no scope definition.
security_txt:
  present: false
  probed_paths:
  - url: https://layerx.co.jp/.well-known/security.txt
    status: 404
  - url: https://bakuraku.jp/.well-known/security.txt
    status: 404
  - url: https://api.bakuraku.layerx.jp/.well-known/security.txt
    status: 404
  - url: https://getaiworkforce.com/.well-known/security.txt
    status: 404
  - url: https://bakuraku-status.jp/.well-known/security.txt
    status: 404
  probed: '2026-08-23'
  note: >-
    The contact exists but is not machine-discoverable. An RFC 9116 security.txt at
    layerx.co.jp carrying Contact: mailto:security@layerx.co.jp and Policy: pointing at
    the existing security_policy page would publish the same fact in a form a scanner can
    read, and costs nothing beyond serving one text file.
bug_bounty:
  present: false
  platforms_checked:
  - HackerOne
  - Bugcrowd
  - Intigriti
  note: No public bug bounty or VDP listing found for LayerX or Bakuraku.
internal_program:
  penetration_testing: >-
    Bakuraku's security page states third-party penetration tests are run regularly with
    prompt remediation of findings, and that intrusion-detection controls are in place.
  ciso: true
  source: https://bakuraku.jp/security/

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/layerx-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.