Paperless Parts · Vulnerability Disclosure

Paperless Parts Vulnerability Disclosure

Vulnerability disclosure

Paperless Parts runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyManufacturingQuotingCNC MachiningSheet MetalERPCRMJob ShopsAerospace and DefensePricingEstimatingIndustrial
Program: Hackerone

Disclosure Policy

Security Contact

Contact
addressobfuscated on the page by a Cloudflare email-protection script; the human-readable address is not exposed to an unauthenticated crawler
Contact
encryption_requestPlease encrypt sensitive details if possible
Contact
methodemail
Contact
noteThe policy says "Email us at [protected address] with a description of the issue, steps to reproduce it, and any supporting evidence". The address itself is behind Cloudflare email-obfuscation, so it is deliberately not transcribed here.
Contact
pgpnot published

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-26'
method: searched
source: https://www.paperlessparts.com/vulnerability-disclosure-policy/
program:
  published: true
  type: vulnerability-disclosure-policy
  url: https://www.paperlessparts.com/vulnerability-disclosure-policy/
  linked_from: https://www.paperlessparts.com/security/
  http_status: 200
  bug_bounty: false
  bounty_note: >-
    "We currently do not offer a paid bug bounty program, but we're grateful for responsible
    disclosures." (verbatim from the policy page)
  platform: none — reported directly by email, not via HackerOne / Bugcrowd / Intigriti
contact:
  method: email
  address: obfuscated on the page by a Cloudflare email-protection script; the human-readable
    address is not exposed to an unauthenticated crawler
  note: >-
    The policy says "Email us at [protected address] with a description of the issue, steps to
    reproduce it, and any supporting evidence". The address itself is behind Cloudflare
    email-obfuscation, so it is deliberately not transcribed here.
  pgp: not published
  encryption_request: "Please encrypt sensitive details if possible"
scope:
  in_scope:
    - '*.paperlessparts.com and its subdomains'
    - Paperless Parts public-facing web applications and APIs
  out_of_scope:
    - third-party services Paperless Parts integrates with
    - social engineering
    - physical security
    - denial-of-service testing
commitments:
  acknowledgement: within 7 business days
  updates: "We'll investigate and keep you updated on our progress"
  resolution_notice: "We'll let you know once the issue is resolved"
researcher_guidelines:
  - give Paperless Parts reasonable time to investigate and fix before public disclosure
  - only interact with accounts and data you own or have explicit permission to test
  - do not access, modify or delete data that is not yours
  - avoid actions that could degrade service for other users
security_txt:
  published: false
  probed:
    - url: https://www.paperlessparts.com/.well-known/security.txt
      status: 404
    - url: https://api.paperlessparts.com/.well-known/security.txt
      status: 404
  note: >-
    A real disclosure policy exists but it is not machine-discoverable — publishing an RFC 9116
    security.txt pointing at this page would be a one-line fix.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/paperless-parts-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.