Osano · Vulnerability Disclosure

Osano Vulnerability Disclosure

Vulnerability disclosure

Osano runs a coordinated vulnerability disclosure program on Hackerone.

CompanyData PrivacyConsent ManagementComplianceGDPRCCPACookie ConsentSubject RightsData MappingVendor RiskPrivacy AssessmentsGovernance Risk Compliance
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-26'
method: probed
source: >-
  Live probes of /.well-known/security.txt on www.osano.com, api.osano.com, uc.api.osano.com,
  developers.osano.com, docs.osano.com and bots.osano.com, plus a search of osano.com and
  developers.osano.com for a disclosure/bug-bounty page.
published: false
note: >-
  NO published vulnerability disclosure surface found. There is no security.txt on any Osano host
  (RFC 9116), no /security or /security/disclosure page (www.osano.com/security returns 404), no
  HackerOne / Bugcrowd / Intigriti program, and no security@ contact stated on a public page. Osano
  does publish that it pen-tests and scans nightly (see security/osano-trust-center.yml) and runs a
  Vanta trust center, but neither tells an outside researcher where to send a finding. This is an
  honest absence, not a probe failure: every path below returned a real status code.
evidence:
- url: https://www.osano.com/.well-known/security.txt
  status: 404
- url: https://api.osano.com/.well-known/security.txt
  status: 404
- url: https://uc.api.osano.com/.well-known/security.txt
  status: 404
- url: https://developers.osano.com/.well-known/security.txt
  status: 404
- url: https://docs.osano.com/.well-known/security.txt
  status: 404
- url: https://bots.osano.com/.well-known/security.txt
  status: 404
- url: https://www.osano.com/security
  status: 404
bug_bounty: null
disclosure_policy_url: null
security_contact: null

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/osano-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.