OptionsAhoy · Vulnerability Disclosure

Optionsahoy Com Vulnerability Disclosure

Vulnerability disclosure

OptionsAhoy runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Equity CompensationTaxStock OptionsFinancial PlanningPersonal FinanceFintechCalculatorsMCPA2AAgent-NativeDeterministicUnited States
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@optionsahoy.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
probe: true
source: well-known/optionsahoy-com-security.txt
docs:
- https://github.com/AlvisoOculus/optionsahoy-mcp/blob/main/SECURITY.md
policy:
- https://github.com/AlvisoOculus/optionsahoy-mcp/blob/main/SECURITY.md
contact:
- mailto:security@optionsahoy.com
acknowledgement_sla: 'We aim to acknowledge reports within three business days.'
disclosure_terms: 'Please do not open a public issue for security reports, and please allow a reasonable window to fix before any public disclosure.'
scope:
- The hosted MCP server at https://optionsahoy.com/mcp
- The REST API under https://optionsahoy.com/api/v1/
- The code in the optionsahoy-mcp repository
out_of_scope: 'Questions about a calculation result or an unexpected number are not security reports (SECURITY.md); those go to a GitHub issue.'
bug_bounty: null
evidence:
- source: well-known/optionsahoy-com-security.txt
  kind: security.txt (RFC 9116) on the apex host
  fetched: '2026-09-19'
  fields: {Contact: 'mailto:security@optionsahoy.com', Preferred-Languages: en, Canonical: 'https://optionsahoy.com/.well-known/security.txt', Expires: '2027-05-16T00:00:00Z'}
  note: No Policy field on the apex file.
- source: well-known/optionsahoy-com-api-security.txt
  kind: security.txt (RFC 9116) on api.optionsahoy.com
  fetched: '2026-09-19'
  fields: {Contact: 'mailto:security@optionsahoy.com', Policy: 'https://optionsahoy.com/security-policy', Expires: 'generated per request'}
  note: The Policy URL it names returns HTTP 404 (probed 2026-09-19). The published policy that does resolve is SECURITY.md in the source repository.
- source: https://github.com/AlvisoOculus/optionsahoy-mcp/blob/main/SECURITY.md
  kind: published security policy
  fetched: '2026-09-19'
  quote: 'Email security@optionsahoy.com with details and steps to reproduce. ... We aim to acknowledge reports within three business days. This matches the disclosure contact published at https://optionsahoy.com/.well-known/security.txt.'
probed_absent:
- {url: 'https://optionsahoy.com/security-policy', status: 404, note: 'The Policy target named by the api-host security.txt.'}
- {url: 'https://optionsahoy.com/security', status: 404}
- {url: 'https://optionsahoy.com/trust', status: 404}
- {url: 'https://hackerone.com/optionsahoy', status: 404}
- {url: 'https://bugcrowd.com/optionsahoy', status: 404}
third_party_scans_claimed:
- {name: MCPSafe, claim: 'Grade A, zero findings (five-model-consensus AIVSS scan)', source: https://optionsahoy.com/for-agents}
- {name: MDN HTTP Observatory, claim: 'A+ (125/100)', source: https://optionsahoy.com/for-agents, note: 'Consistent with the HSTS-preload/CSP/COOP headers observed on /openapi.json.'}
data_posture: 'SECURITY.md: no accounts, no authentication, no stored user data; inputs are not retained; telemetry records only tool name, success/error, client name and country; computation runs offline from compiled tax tables.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/optionsahoy-com-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.