generated: '2026-09-03'
method: searched
probe: true
source: https://leadping.ai/docs/trust/responsible-disclosure
policy_url: https://leadping.ai/docs/trust/responsible-disclosure
policy_http_status: 200
summary: >-
Leadping publishes a written responsible-disclosure policy inside its Trust Center and an RFC 9116
security.txt on BOTH leadping.ai and api.leadping.ai. There is no bug bounty and no paid reward
program — no HackerOne, Bugcrowd, Intigriti or Leadping-hosted bounty page exists — and the policy
explicitly declines to authorize testing.
contact:
- mailto:security@leadping.ai
security_txt:
hosts:
- host: leadping.ai
url: https://leadping.ai/.well-known/security.txt
status: 200
file: well-known/leadping-security.txt
- host: api.leadping.ai
url: https://api.leadping.ai/.well-known/security.txt
status: 200
file: well-known/leadping-api-security.txt
note: New since 2026-08-18; identical body to the apex copy.
fields:
contact: mailto:security@leadping.ai
expires: '2030-12-31T00:59:00Z'
missing_fields:
- Policy
- Encryption
- Acknowledgments
- Preferred-Languages
- Canonical
note: >-
The security.txt carries only Contact and Expires. It does NOT carry a Policy field, so a scanner
reading only security.txt would never find the responsible-disclosure page — the two surfaces are
not linked to each other. Adding "Policy: https://leadping.ai/docs/trust/responsible-disclosure"
would be a one-line fix. The Expires value is also unusually distant (2030), where RFC 9116
recommends under a year.
policy:
reporting_channel: email to security@leadping.ai
safe_harbor: false
safe_harbor_note: >-
The policy grants NO safe harbour and says so plainly: "This reporting channel does not authorize
scanning, probing, exploitation, disruption, or access to accounts, data, integrations, carriers,
providers, or systems you do not own." It is a report-what-you-happen-to-find channel, not an
authorized-testing program.
requested_in_report:
- what was observed
- the affected account, source, integration, number, page, endpoint or workflow, if safe to share
- approximate date, time and time zone
- reproduction steps using only authorized access
- request IDs, timestamps, screenshots or redacted logs
- contact information for follow-up
do_not_send:
- passwords
- full keys
- tokens
- payment-card data
- private keys
- another customer's information
secure_transfer_note: >-
Leadping offers to provide a safer transfer method if sensitive evidence is required, but
publishes no PGP key and no Encryption field in security.txt.
stop_testing_conditions:
- you encounter data or access outside your account
- continued activity could change or delete data
- the test could affect service availability
- the issue involves a third-party system
- Leadping asks you to stop
prohibited:
- accessing, copying, modifying, deleting, exporting or disclosing data that is not yours
- bypassing authentication, authorization, billing, carrier, compliance, rate-limit or abuse controls
- automated scans, denial-of-service tests, spam, credential stuffing, password spraying
- testing customer systems, carriers, providers or other third parties without authorization
- social engineering or phishing of employees, customers, providers or partners
- public disclosure before Leadping has investigated
coordinated_disclosure: true
coordinated_disclosure_note: >-
Public disclosure before investigation is prohibited, but no disclosure deadline, no
acknowledgement SLA and no remediation timeline is published.
response_process: >-
Leadping reviews the report and may request clarification, then may contain risk, rotate
credentials, restrict access, coordinate with providers, notify affected parties or take other
protective action. Leadping reserves the right to withhold internal findings, customer data,
infrastructure details, provider information and remediation specifics.
bug_bounty:
exists: false
platforms_checked:
- HackerOne
- Bugcrowd
- Intigriti
note: >-
No bounty program, no reward schedule, no hall of fame and no Acknowledgments field. Consistent
with the policy's no-safe-harbour posture.
gaps:
- security.txt has no Policy field pointing at the published disclosure policy.
- No PGP key or Encryption field, despite the policy anticipating sensitive evidence.
- No acknowledgement SLA, triage timeline or disclosure deadline.
- No safe harbour, so a good-faith researcher has no stated protection.
evidence:
- source: https://leadping.ai/docs/trust/responsible-disclosure
status: 200
kind: written responsible-disclosure policy
fetched: '2026-09-03'
- source: https://leadping.ai/.well-known/security.txt
status: 200
kind: RFC 9116 security.txt
fetched: '2026-09-03'
- source: https://api.leadping.ai/.well-known/security.txt
status: 200
kind: RFC 9116 security.txt
fetched: '2026-09-03'
- source: https://leadping.ai/docs/trust/overview
status: 200
kind: Trust Center index linking the disclosure policy
fetched: '2026-09-03'
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/leadping-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
A second provider on the same verified email joins the account you already have.