LevelBlue · Vulnerability Disclosure

Levelblue Vulnerability Disclosure

Vulnerability disclosure

LevelBlue runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyEnterpriseCybersecuritySecurityThreat IntelligenceManaged SecuritySIEMThreat DetectionIncident ResponseCompliance
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy
Policy

Security Contact

Contact
mailto:levelblue@submit.bugcrowd.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: well-known/levelblue-security.txt

policy:
- https://docs.levelblue.com/documentation/how-to-submit-a-security-issue
- https://hackerone.com/att
- https://www.levelblue.com/legal/privacy-policy

contact:
- mailto:levelblue@submit.bugcrowd.com

programs:
- name: LevelBlue vulnerability submission (Bugcrowd)
  platform: Bugcrowd
  intake: mailto:levelblue@submit.bugcrowd.com
  evidence: Contact field of https://www.levelblue.com/.well-known/security.txt
- name: AT&T Bug Bounty Program
  platform: HackerOne
  url: https://hackerone.com/att
  evidence: >-
    The LevelBlue documentation page "How to Submit a Security Issue to LevelBlue"
    directs researchers to disclose through the AT&T Bug Bounty Program managed by
    HackerOne, where program guidelines, exclusions, terms, reporting process and
    awarding process are published.
  note: >-
    Inherited from LevelBlue's origin as AT&T Cybersecurity; the docs page still refers to
    AT&T as the operating entity.

security_txt:
  url: https://www.levelblue.com/.well-known/security.txt
  file: well-known/levelblue-security.txt
  standard: RFC 9116
  fields:
    contact: mailto:levelblue@submit.bugcrowd.com
    expires: '2027-02-01T00:00:00.000Z'
    preferred_languages: en
    canonical: https://www.levelblue.com/.well-known/security.txt
    policy: https://www.levelblue.com/legal/privacy-policy
    hiring: https://jobs.dayforcehcm.com/en-US/twh/CANDIDATEPORTAL?searchText=security
  observations:
  - >-
      The Policy field points at the general website privacy policy rather than a
      vulnerability disclosure policy — the actual disclosure policy lives on the
      HackerOne program page and the docs "How to Submit a Security Issue" page.
  - No Encryption, Acknowledgments or CSAF field is published.

submission_guidance:
  source: https://docs.levelblue.com/documentation/how-to-submit-a-security-issue
  requested_detail:
  - Steps and any additional information needed to reproduce the issue.
  - For XSS, an exploit that at minimum pops an alert; showing the auth cookie is preferred.
  - For CSRF, a proper case where a third party causes the logged-in victim to perform an action.
  - For SQL injection, an exploit extracting database data rather than only producing an error.
  - HTTP request/response captures or packet captures.

evidence:
- source: well-known/levelblue-security.txt
  kind: security.txt
- source: https://docs.levelblue.com/documentation/how-to-submit-a-security-issue
  kind: disclosure-page
  keywords: [bug bounty, hackerone, responsible disclosure, security vulnerability]

trust_center:
  found: false
  checked:
  - https://trust.levelblue.com (no DNS resolution)
  - https://www.levelblue.com/trust (404)
  - https://www.levelblue.com/security (404)
  - https://www.levelblue.com/company/compliance (404)
  note: >-
    No public trust center or certifications page was found, so no TrustCenter or
    Compliance pointer is emitted. LevelBlue documents compliance as a product capability
    (PCI DSS reporting in USM Anywhere, FedRAMP authorization for LevelBlue TDR for Gov) —
    see conformance/levelblue-conformance.yml — but publishes no corporate certification
    inventory.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/levelblue-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.