Level2 · Vulnerability Disclosure

Level2 Vulnerability Disclosure

Vulnerability disclosure

Level2 runs a published vulnerability disclosure programme with a named contact, a stated acknowledgement target, an explicit in-scope domain list and an in-scope vulnerability-class list. It is a coordinated-disclosure programme, not a paid bug bounty.

Level2 runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

TradingFintechFinancial ServicesAutomationNo-CodeBacktestingStrategiesBrokerageMarket DataPrediction Markets
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@trylevel2.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-17'
method: searched
probe: true
source: >-
  https://www.trylevel2.com/.well-known/security.txt (HTTP 200, text/plain) and the policy it points
  at, https://www.trylevel2.com/security (HTTP 200)
docs: https://www.trylevel2.com/security
description: >-
  Level2 runs a published vulnerability disclosure programme with a named contact, a stated
  acknowledgement target, an explicit in-scope domain list and an in-scope vulnerability-class list.
  It is a coordinated-disclosure programme, not a paid bug bounty.
program:
  type: vulnerability-disclosure
  name: Vulnerability Disclosure Program
  bounty: false
  platform: null
  platform_note: >-
    Not run on HackerOne, Bugcrowd or Intigriti — reports go directly to the security address.
  safe_harbor_stated: false
policy:
  - https://www.trylevel2.com/security
contact:
  - mailto:security@trylevel2.com
preferred_languages:
  - en
response_targets:
  acknowledgement: 72 hours
  quote: 'We aim to acknowledge vulnerability reports within 72 hours.'
  process:
    - Security team reviews the submission and begins investigating.
    - Level2 may contact the reporter for additional information.
    - Verified issues are resolved as quickly as possible.
    - The reporter is notified when the vulnerability has been resolved.
disclosure_terms: >-
  Reporters are asked not to disclose publicly until Level2 has had reasonable time to investigate
  and address the issue.
report_contents_requested:
  - A detailed description of the vulnerability.
  - Step-by-step instructions to reproduce the issue.
  - Proof-of-concept scripts, screenshots or logs.
  - The potential security impact of the issue.
  - Any suggested remediation if available.
scope:
  domains:
    - trylevel2.com
    - '*.trylevel2.com'
  note: >-
    The Bytemine hosts (bytemine.io, guide.bytemine.io, valhalla.bytemine.workers.dev), which carry
    the legacy signal API and its documentation, are NOT named in the in-scope domain list even though
    Bytemine Technologies Ltd is the company behind Level2.
  vulnerability_classes:
    - Authentication bypass or account takeover
    - Broken access control or privilege escalation
    - Insecure Direct Object References (IDOR)
    - Cross-Site Scripting (XSS)
    - Cross-Site Request Forgery (CSRF)
    - Server-Side Request Forgery (SSRF)
    - SQL or NoSQL injection
    - Remote Code Execution (RCE)
    - Sensitive data exposure or unintended information disclosure
    - Subdomain takeover
    - Security misconfigurations with meaningful security impact
evidence:
  - source: https://www.trylevel2.com/.well-known/security.txt
    kind: security.txt (RFC 9116, live probe)
    status: 200
    file: well-known/level2-security.txt
  - source: https://www.trylevel2.com/security
    kind: disclosure policy page (live fetch)
    status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/level2-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.