MontyCloud · Vulnerability Disclosure

Montycloud Vulnerability Disclosure

Vulnerability disclosure

MontyCloud runs a coordinated vulnerability disclosure program on Hackerone.

CloudCloud OperationsManaged Service ProvidersGovernanceComplianceCost ManagementArtificial IntelligenceAgentsMCPMulti-TenantInfrastructure
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

montycloud-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-26'
method: searched
source: https://montycloud.com/data-security-statement/
program:
  formal_vdp: false
  bug_bounty: false
  safe_harbor: not_stated
  platform: none
  note: >-
    MontyCloud publishes no responsible-disclosure policy, no bug bounty (no HackerOne, Bugcrowd or
    Intigriti listing), no security.txt and no /security or /responsible-disclosure page. What it
    does publish, on two separate first-party pages, is a named security reporting channel — which
    is the minimum a researcher needs to reach them, and is why this artifact is written rather
    than omitted.
contacts:
  - email: security@montycloud.com
    role: security questions and reports
    stated_on: https://montycloud.com/data-security-statement/
    also_on: https://montycloud.com/mcp-server-security-statement/
    quote: >-
      "If you have any questions or require further information regarding our security practices,
      please do not hesitate to contact our security team at security@montycloud.com"
  - email: infosec@montycloud.com
    role: security documentation, questionnaires, SOC 2 and pen-test summaries under NDA
    stated_on: https://montycloud.com/trust-center/
  - email: privacy@montycloud.com
    role: privacy and data subject rights
    stated_on: https://montycloud.com/trust-center/
response_target:
  detail: >-
    "The MontyCloud InfoSec team aims to respond to all security review requests within 2 business
    days." This is a stated target for security REVIEW requests, not an incident/disclosure SLA.
  source: https://montycloud.com/trust-center/
assurance:
  penetration_testing:
    performed: true
    cadence: regular
    party: independent third-party security firm
    disclosure: summaries available to customers under NDA via infosec@montycloud.com
    source: https://montycloud.com/trust-center/
probes:
  - url: https://montycloud.com/.well-known/security.txt
    status: 404
  - url: https://support.montycloud.com/.well-known/security.txt
    status: 404
  - url: https://api.montycloud.com/.well-known/security.txt
    status: 403
    note: AWS API Gateway/WAF blanket Forbidden, not a confirmed absence
probes_checked: '2026-08-26'
gap: >-
  Publishing an RFC 9116 /.well-known/security.txt naming security@montycloud.com, plus a short
  disclosure policy page, would convert an already-real reporting channel into a discoverable one.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/montycloud-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.