MolTrust · Vulnerability Disclosure

Moltrust Ch Vulnerability Disclosure

Vulnerability disclosure

MolTrust runs a coordinated vulnerability disclosure program on Hackerone.

AI AgentsAgent IdentityDecentralized IdentityVerifiable CredentialsTrust and SafetyAgent AuthorizationComplianceBlockchainA2AMCPx402Agent-Native
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
source: https://raw.githubusercontent.com/MoltyCel/moltrust-api/main/README.md + https://moltrust.ch/terms.html
  + well-known probes 2026-09-19 + probe-security-programs.py (vdp=none trust=none)
checked: '2026-09-19'
summary: MolTrust publishes a first-party security contact - security@moltrust.ch, in the "Contact" section of the
  public moltrust-api GitHub README - but no /.well-known/security.txt on any host, no security or responsible-disclosure
  page on moltrust.ch, no SECURITY.md in the repo, and no bug bounty. The channel is real and first-party; the program
  around it is undocumented. probe-security-programs.py found nothing because it does not read GitHub READMEs.
program:
  published: true
  kind: email-only
  contact: mailto:security@moltrust.ch
  quote: '"## Contact\nsecurity@moltrust.ch"'
  location: https://github.com/MoltyCel/moltrust-api#readme
  secondary_contact: 'info@moltrust.ch for compromised API keys (Terms of Service section 3: "If you suspect your
    API key has been compromised, contact us immediately at info@moltrust.ch")'
policy:
  page: null
  safe_harbor_documented: false
  scope_documented: false
  response_sla_documented: false
  disclosure_timeline_documented: false
  rewards: none-published
bug_bounty:
  platform: null
  hackerone: false
  bugcrowd: false
  intigriti: false
  note: No bounty program located on any MolTrust host or the major platforms.
security_txt:
  served: false
  probes:
  - url: https://moltrust.ch/.well-known/security.txt
    status: 404
  - url: https://moltrust.ch/security.txt
    status: 404
  - url: https://api.moltrust.ch/.well-known/security.txt
    status: 404
  - url: https://uresolver.moltrust.ch/.well-known/security.txt
    status: 404
  - url: https://status.moltrust.ch/.well-known/security.txt
    status: 404
  note: RFC 9116 is not implemented. A security.txt naming the existing security@moltrust.ch address would be a
    one-file fix on a static nginx host.
security_md:
  probes:
  - url: https://raw.githubusercontent.com/MoltyCel/moltrust-api/main/SECURITY.md
    status: 404
  - url: https://raw.githubusercontent.com/MoltyCel/.github/main/SECURITY.md
    status: 404
public_security_record:
  note: The moltrust-api repo publishes an incident write-up (docs/incidents/2026-05-22_test-key-exposure.md), a
    security_check.sh script, dependency-pinning and PQC dual-signature ADRs, and a blog post "Hardening the MolTrust
    Trust Stack" (2026-03-26). Evidence of practice, not a disclosure policy.
pointer_basis: Security pointer emitted on the strength of the published first-party security@moltrust.ch contact;
  it asserts a disclosure channel exists, not a policy.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/moltrust-ch-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.