Leadping · Vulnerability Disclosure

Leadping Vulnerability Disclosure

Vulnerability disclosure

Leadping runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Lead ManagementSales & marketing automationSMS MessagingA2P 10DLCCPaaSCommunicationsVoice/callingCompliance & consentagent-nativeMCPLead intakeConversationsAutomationsSuppression & opt-outWebhook
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
mailto:security@leadping.ai

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-03'
method: searched
probe: true
source: https://leadping.ai/docs/trust/responsible-disclosure
policy_url: https://leadping.ai/docs/trust/responsible-disclosure
policy_http_status: 200
summary: >-
  Leadping publishes a written responsible-disclosure policy inside its Trust Center and an RFC 9116
  security.txt on BOTH leadping.ai and api.leadping.ai. There is no bug bounty and no paid reward
  program — no HackerOne, Bugcrowd, Intigriti or Leadping-hosted bounty page exists — and the policy
  explicitly declines to authorize testing.
contact:
  - mailto:security@leadping.ai
security_txt:
  hosts:
    - host: leadping.ai
      url: https://leadping.ai/.well-known/security.txt
      status: 200
      file: well-known/leadping-security.txt
    - host: api.leadping.ai
      url: https://api.leadping.ai/.well-known/security.txt
      status: 200
      file: well-known/leadping-api-security.txt
      note: New since 2026-08-18; identical body to the apex copy.
  fields:
    contact: mailto:security@leadping.ai
    expires: '2030-12-31T00:59:00Z'
  missing_fields:
    - Policy
    - Encryption
    - Acknowledgments
    - Preferred-Languages
    - Canonical
  note: >-
    The security.txt carries only Contact and Expires. It does NOT carry a Policy field, so a scanner
    reading only security.txt would never find the responsible-disclosure page — the two surfaces are
    not linked to each other. Adding "Policy: https://leadping.ai/docs/trust/responsible-disclosure"
    would be a one-line fix. The Expires value is also unusually distant (2030), where RFC 9116
    recommends under a year.
policy:
  reporting_channel: email to security@leadping.ai
  safe_harbor: false
  safe_harbor_note: >-
    The policy grants NO safe harbour and says so plainly: "This reporting channel does not authorize
    scanning, probing, exploitation, disruption, or access to accounts, data, integrations, carriers,
    providers, or systems you do not own." It is a report-what-you-happen-to-find channel, not an
    authorized-testing program.
  requested_in_report:
    - what was observed
    - the affected account, source, integration, number, page, endpoint or workflow, if safe to share
    - approximate date, time and time zone
    - reproduction steps using only authorized access
    - request IDs, timestamps, screenshots or redacted logs
    - contact information for follow-up
  do_not_send:
    - passwords
    - full keys
    - tokens
    - payment-card data
    - private keys
    - another customer's information
  secure_transfer_note: >-
    Leadping offers to provide a safer transfer method if sensitive evidence is required, but
    publishes no PGP key and no Encryption field in security.txt.
  stop_testing_conditions:
    - you encounter data or access outside your account
    - continued activity could change or delete data
    - the test could affect service availability
    - the issue involves a third-party system
    - Leadping asks you to stop
  prohibited:
    - accessing, copying, modifying, deleting, exporting or disclosing data that is not yours
    - bypassing authentication, authorization, billing, carrier, compliance, rate-limit or abuse controls
    - automated scans, denial-of-service tests, spam, credential stuffing, password spraying
    - testing customer systems, carriers, providers or other third parties without authorization
    - social engineering or phishing of employees, customers, providers or partners
    - public disclosure before Leadping has investigated
  coordinated_disclosure: true
  coordinated_disclosure_note: >-
    Public disclosure before investigation is prohibited, but no disclosure deadline, no
    acknowledgement SLA and no remediation timeline is published.
  response_process: >-
    Leadping reviews the report and may request clarification, then may contain risk, rotate
    credentials, restrict access, coordinate with providers, notify affected parties or take other
    protective action. Leadping reserves the right to withhold internal findings, customer data,
    infrastructure details, provider information and remediation specifics.
bug_bounty:
  exists: false
  platforms_checked:
    - HackerOne
    - Bugcrowd
    - Intigriti
  note: >-
    No bounty program, no reward schedule, no hall of fame and no Acknowledgments field. Consistent
    with the policy's no-safe-harbour posture.
gaps:
  - security.txt has no Policy field pointing at the published disclosure policy.
  - No PGP key or Encryption field, despite the policy anticipating sensitive evidence.
  - No acknowledgement SLA, triage timeline or disclosure deadline.
  - No safe harbour, so a good-faith researcher has no stated protection.
evidence:
  - source: https://leadping.ai/docs/trust/responsible-disclosure
    status: 200
    kind: written responsible-disclosure policy
    fetched: '2026-09-03'
  - source: https://leadping.ai/.well-known/security.txt
    status: 200
    kind: RFC 9116 security.txt
    fetched: '2026-09-03'
  - source: https://api.leadping.ai/.well-known/security.txt
    status: 200
    kind: RFC 9116 security.txt
    fetched: '2026-09-03'
  - source: https://leadping.ai/docs/trust/overview
    status: 200
    kind: Trust Center index linking the disclosure policy
    fetched: '2026-09-03'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/leadping-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.