Limrun · Vulnerability Disclosure

Limrun Vulnerability Disclosure

Vulnerability disclosure

Limrun runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyMobileiOSAndroidSimulatorsEmulatorsCloud InfrastructureContinuous IntegrationDeveloper ToolsTestingAgentsModel Context ProtocolSandboxesXcode
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
contact@limrun.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://github.com/limrun-inc/typescript-sdk/blob/main/SECURITY.md
summary: >-
  Limrun publishes no /.well-known/security.txt, no responsible-disclosure page, and no bug bounty
  program. The automated probe (probe-security-programs.py) returned no hit on any host. The one
  published security policy in Limrun's control is the SECURITY.md carried in each SDK repository -
  Stainless boilerplate, but it names a Limrun contact address for issues with the services
  themselves. Recorded with that scope stated plainly rather than presented as a full VDP.
policy:
- https://github.com/limrun-inc/typescript-sdk/blob/main/SECURITY.md
contact:
- contact@limrun.com
bug_bounty:
  program: none
  platforms_checked:
  - HackerOne
  - Bugcrowd
  - Intigriti
security_txt:
  present: false
  hosts_checked:
  - lim.run
  - docs.limrun.com
  - api.limrun.com
scope_caveat: >-
  The SECURITY.md is generated by Stainless for the SDK and routes SDK vulnerabilities to
  security@stainless.com. For the Limrun service itself it directs reporters to contact@limrun.com,
  which is a general contact address rather than a dedicated security channel. There is no stated
  disclosure window, safe-harbor language, or PGP key.
evidence:
- source: https://github.com/limrun-inc/typescript-sdk/blob/main/SECURITY.md
  kind: security-policy
  quote: >-
    Please contact contact@limrun.com for any questions or concerns regarding the security of our
    services.
- source: probe-security-programs.py
  kind: probe
  result: 'vdp=none trust=none'
pages_checked:
- url: https://lim.run/security
  status: 404
- url: https://trust.limrun.com
  status: no-dns
- url: https://lim.run/privacy
  status: 404
- url: https://lim.run/terms
  status: 404
gap: >-
  A dedicated security.txt and a responsible-disclosure page would be the highest-value additions
  here, particularly for a platform that runs customer source code and signing material on shared
  cloud Macs.