Losant · Vulnerability Disclosure

Losant Vulnerability Disclosure

Vulnerability disclosure

Losant runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

IoTInternet of ThingsDevicesEdge ComputeEmbeddedMQTTIndustrial IoTTelemetryWorkflow-AutomationVisual Workflow EngineDashboardsTime SeriesConnected ProductsEnterprise
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
hello@losant.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-26'
method: searched
probe: true
source: https://github.com/Losant/losant-mcp-server/blob/main/SECURITY.md
scope: repository
scope_note: |
  IMPORTANT - read the scope. Losant publishes NO platform-wide vulnerability disclosure policy: there is
  no /.well-known/security.txt on any Losant host (api.losant.com answers 405, www.losant.com and
  mcp.losant.com answer 404, probed 2026-08-26), no /security or /responsible-disclosure page on
  www.losant.com (404), and no bug bounty program on HackerOne, Bugcrowd or Intigriti was found. What
  Losant does publish is a real, first-party SECURITY.md in its open-source MCP server repository, with a
  named reporting address and stated response times. That document governs the MCP server project; it is
  the only published disclosure channel and is recorded here as such rather than being generalised into a
  platform policy Losant has not written.
policy:
  - https://github.com/Losant/losant-mcp-server/blob/main/SECURITY.md
contact:
  - hello@losant.com
channel: email
public_disclosure_prohibited: 'Reporters are asked not to use public GitHub issues.'
response_commitments:
  acknowledgement: within 48 hours
  update: within 5 business days
  coordination: 'disclosure timing coordinated with the reporter'
  credit: 'credited in the security advisory unless the reporter prefers anonymity'
requested_report_contents:
  - type of vulnerability
  - full paths of affected source files
  - location of the affected code (tag/branch/commit or URL)
  - special configuration needed to reproduce
  - step-by-step reproduction
  - proof-of-concept or exploit code, if possible
  - impact and how an attacker might exploit it
supported_versions:
  - {version: '1.0.x', supported: true}
bug_bounty: null
security_overview: https://docs.losant.com/references/security/
evidence:
  - {source: 'https://github.com/Losant/losant-mcp-server/blob/main/SECURITY.md', kind: security-policy, http_status: 200}
  - {source: 'https://www.losant.com/.well-known/security.txt', kind: probe, http_status: 404}
  - {source: 'https://api.losant.com/.well-known/security.txt', kind: probe, http_status: 405}
  - {source: 'https://mcp.losant.com/.well-known/security.txt', kind: probe, http_status: 404}
  - {source: 'https://www.losant.com/security', kind: probe, http_status: 404}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/losant-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.