Mindtickle · Vulnerability Disclosure

Mindtickle Vulnerability Disclosure

Vulnerability disclosure

Mindtickle publishes a full responsible-disclosure policy with a named scope (explicitly including the Open API at api.mindtickle.com), an exclusion list, researcher guidelines, a single reporting address, CFAA/DMCA safe harbour, and a published hall of fame naming 26 researchers. Bug-bounty awards exist but are discretionary and limited to critical/high-impact findings.

Mindtickle runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Sales EnablementRevenue ProductivitySales ReadinessCoachingConversation IntelligenceLearning ManagementContent ManagementCall AIRevenue Intelligence
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
infosec@mindtickle.com

Source

Vulnerability Disclosure

mindtickle-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.mindtickle.com/responsible-vulnerability-disclosure/
name: Mindtickle Responsible Vulnerability Disclosure Policy
description: >-
  Mindtickle publishes a full responsible-disclosure policy with a named scope
  (explicitly including the Open API at api.mindtickle.com), an exclusion list,
  researcher guidelines, a single reporting address, CFAA/DMCA safe harbour, and
  a published hall of fame naming 26 researchers. Bug-bounty awards exist but
  are discretionary and limited to critical/high-impact findings.

policy:
- https://www.mindtickle.com/responsible-vulnerability-disclosure/
contact:
- infosec@mindtickle.com
security_policy: https://www.mindtickle.com/security/policy/

scope:
- admin.mindtickle.com (platform admin site)
- '*.mindtickle.com (platform learning sites and other platform pages)'
- api.mindtickle.com (Open API)
- iOS mobile application
- Android mobile application

exclusions:
- Denial of Service (DoS) / Distributed Denial of Service (DDoS)
- Cross-origin resource sharing (CORS)
- WordPress XML-RPC.php
- Server-side request forgery (SSRF)
- Brute force attack on any page
- Session timeout (configured per customer)
- Masqueraded file upload via extension change
- Upload/download of viruses or malicious files
- Rate limiting restrictions imposed by the platform or API
- Missing captcha
- Browser autocomplete / saved passwords
- Known third-party library vulnerabilities not exploitable on the platform
- Missing HTTP security headers with no demonstrated threat
- Missing Secure/HTTPOnly flags on non-sensitive cookies
- Learning site settings enumeration of non-sensitive information
- Fingerprinting, host header and banner grabbing
- Descriptive error messages (stack traces, server responses)
- Social engineering (phishing, vishing)
- Physical security of offices or personnel

bug_bounty:
  offered: true
  program: self-managed
  platform: null
  discretionary: true
  eligibility: critical / high impact vulnerabilities that penetrate systems or affect customer data
  note: >-
    No HackerOne, Bugcrowd or Intigriti program was found. Awards are granted,
    modified or denied at Mindtickle's discretion and the reporter carries the
    tax liability.

safe_harbor:
  offered: true
  statutes: [Computer Fraud and Abuse Act (CFAA), Digital Millennium Copyright Act (DMCA)]

hall_of_fame:
  published: true
  url: https://www.mindtickle.com/responsible-vulnerability-disclosure/
  researchers_named: 26

security_txt:
  served: false
  note: >-
    No RFC 9116 security.txt is served on any Mindtickle host. www.mindtickle.com
    answers /.well-known/security.txt with HTTP 200 carrying its own 404 HTML page
    (a soft-404, not a document); api.mindtickle.com returns 400 and
    app.mindtickle.com returns 404. Publishing a security.txt pointing at
    infosec@mindtickle.com and the policy URL would be a one-file fix.

evidence:
- source: https://www.mindtickle.com/responsible-vulnerability-disclosure/
  http_status: 200
  kind: disclosure-policy
  keywords: [responsible disclosure, vulnerability, bug bounty, safe harbor, infosec@]
- source: https://www.mindtickle.com/security/policy/
  http_status: 200
  kind: security-policy
- source: https://www.mindtickle.com/.well-known/security.txt
  http_status: 200
  kind: security.txt
  real_document: false
  note: soft-404 HTML shell, not an RFC 9116 document

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mindtickle-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.