Lindy · Vulnerability Disclosure

Lindy Vulnerability Disclosure

Vulnerability disclosure

Vulnerability-disclosure posture for Lindy. Lindy publishes a real security page describing proactive testing and an incident-response playbook, and offers a named security contact — but no machine-readable disclosure surface: no security.txt on any host, no published disclosure policy page, no safe harbour statement, and no bug bounty program on HackerOne, Bugcrowd or Intigriti.

Lindy runs a coordinated vulnerability disclosure program on Hackerone.

AI AgentsAI AutomationAgentic AIMCPWorkflow-AutomationVirtual AssistantProductivityEmailMeetingsSlack
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

lindy-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-29'
method: searched
source: https://www.lindy.ai/security
provider: Lindy
providerId: lindy
description: >-
  Vulnerability-disclosure posture for Lindy. Lindy publishes a real security
  page describing proactive testing and an incident-response playbook, and
  offers a named security contact — but no machine-readable disclosure surface:
  no security.txt on any host, no published disclosure policy page, no safe
  harbour statement, and no bug bounty program on HackerOne, Bugcrowd or
  Intigriti.
security_page:
  url: https://www.lindy.ai/security
  status: 200
  claims:
    - Regular vulnerability scans and penetration tests
    - Real-time monitoring with unusual activity flagged and routed to the team
    - Incident-response playbook with defined roles, timelines and communication
  contact:
    label: Contact Security
    route: contact form linked from the security page
    generic_support: support@lindy.ai
security_txt:
  published: false
  probes:
    - url: https://www.lindy.ai/.well-known/security.txt
      status: 404
    - url: https://lindy.ai/.well-known/security.txt
      status: 404
    - url: https://docs.lindy.ai/.well-known/security.txt
      status: 404
    - url: https://public.lindy.ai/.well-known/security.txt
      status: 404
disclosure_policy:
  published: false
  url: null
safe_harbor:
  published: false
bug_bounty:
  program: none-found
  platforms_checked:
    - HackerOne
    - Bugcrowd
    - Intigriti
trust_center:
  url: https://app.drata.com/trust/9cb791f0-0c38-11ee-865f-029d78a187d9
  artifact: security/lindy-trust-center.yml
  note: >-
    The trust center is the documented route for requesting SOC 2 reports and
    compliance summaries. It returned 403 to our crawler (an ordinary Drata bot
    policy, not a dead page) and is linked from both www.lindy.ai/security and
    the site footer.
recommendation: >-
  Publishing an RFC 9116 /.well-known/security.txt on www.lindy.ai naming the
  existing security contact would make an already-real program machine-readable
  at essentially zero cost.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lindy-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.