Memo Bank · Vulnerability Disclosure

Memo Bank Vulnerability Disclosure

Vulnerability disclosure

Memo Bank runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyFintech InsurtechBankingBusiness BankingPaymentsSEPASEPA Direct Debitvirtual-ibanWire TransfersOpen BankingPSD2Berlin GroupWebhookMCPFrance
Program: Hackerone

Disclosure Policy

Security Contact

Contact
{"address" => "security@memo.bank", "channel" => "dns-caa-iodef", "discoverable_by" => "dig CAA memo.bank", "verified" => true}
Contact
{"address" => "openbanking@memo.bank", "channel" => "marketplace registration contact", "note" => "Not a security contact; recorded only to distinguish it from the address above."}

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-17'
method: probed
probe: true
source: security/memo-bank-domain-security.yml
published_policy: false
program: none
note: >-
  Memo Bank publishes NO vulnerability disclosure policy, no responsible-disclosure page, no bug bounty and
  no security.txt. The one machine-readable security contact that does exist was found in DNS: the memo.bank
  CAA record set includes an RFC 8659 iodef entry pointing at security@memo.bank. That is a real,
  provider-published, verifiable reporting address, so it is recorded here - but it is a certificate-incident
  reporting hint, not a disclosure programme, and a researcher would only find it by querying CAA records.
  Because there is no published policy PAGE, no `Security` pointer is emitted in apis.yml: doing so would
  credit Memo Bank with a disclosure programme it does not advertise. This is deliberately recorded as an
  honest partial rather than upgraded.
contact:
- address: security@memo.bank
  channel: dns-caa-iodef
  discoverable_by: dig CAA memo.bank
  verified: true
- address: openbanking@memo.bank
  channel: marketplace registration contact
  note: Not a security contact; recorded only to distinguish it from the address above.
policy: []
bug_bounty:
  present: false
  platforms_checked:
  - platform: HackerOne
    url: https://hackerone.com/memobank
    status: 404
  - platform: Bugcrowd
    url: https://bugcrowd.com/memobank
    status: 404
  - platform: Intigriti
    checked: true
    found: false
security_txt:
  present: false
  probed:
  - url: https://memo.bank/.well-known/security.txt
    status: 404
  - url: https://memo.bank/security.txt
    status: 200
    soft_404: true
    note: >-
      Returns the site's Next.js SPA shell with lang="security.txt" rather than RFC 9116 content. A naive
      probe that only checks the status code would wrongly credit this as a hit.
  - url: https://api.memo.bank/.well-known/security.txt
    status: 404
  - url: https://api.sandbox.memo.bank/.well-known/security.txt
    status: 404
  - url: https://docs.api.memo.bank/.well-known/security.txt
    status: 404
  - url: https://client.memo.bank/.well-known/security.txt
    status: 404
disclosure_pages_probed:
- url: https://memo.bank/en/responsible-disclosure/
  status: 404
- url: https://memo.bank/en/vulnerability-disclosure/
  status: 404
- url: https://memo.bank/en/bug-bounty/
  status: 404
- url: https://memo.bank/en/about/security-operations/
  status: 200
  contains_disclosure_policy: false
  note: >-
    The security page describes controls (two-step authentication, TLS, encryption at rest, European hosting
    on GCP/AWS, GDPR, an audited core banking platform) and names the ECB/ACPR/AMF regulators, but contains
    no vulnerability reporting instructions, no security contact address and no safe-harbour statement.
evidence:
- source: security/memo-bank-domain-security.yml
  kind: dns-caa
  record: 0 iodef "mailto:security@memo.bank"
  domain: memo.bank
  probed: '2026-08-17'
- source: https://memo.bank/.well-known/security.txt
  kind: negative-probe
  http_status: 404
  probed: '2026-08-17'
- source: https://memo.bank/security.txt
  kind: soft-200
  http_status: 200
  content_type: text/html
  probed: '2026-08-17'
recommended_to_provider:
- >-
  Publish /.well-known/security.txt (RFC 9116) on memo.bank and api.memo.bank with Contact,
  Preferred-Languages, Canonical and Expires. The contact address already exists in the CAA record, so this
  is a five-line file, and it is the single cheapest security-posture improvement available to them.
- >-
  Publish a responsible-disclosure page with scope and a safe-harbour statement. As an ECB-licensed credit
  institution with a public payments API, Memo Bank is a higher-value research target than most, and
  researchers currently have no documented route in.
gaps:
- No RFC 9116 security.txt on any host.
- No responsible-disclosure or vulnerability-disclosure page.
- No bug bounty programme on any major platform.
- No safe-harbour statement for good-faith researchers.
- No published PGP key or Preferred-Languages hint.
- The only machine-readable security contact is hidden in a DNS CAA iodef record.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/memo-bank-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.