Peek · Vulnerability Disclosure

Peek Vulnerability Disclosure

Vulnerability disclosure

Peek runs a coordinated vulnerability disclosure program on Hackerone.

CompanyTravelTourismBookingReservationsExperienceTours and ActivitiesPaymentsMarketplaceMCPOCTOSoftware-as-a-Service
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

peek-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-26'
method: probed
source: https://www.peekpro.com/.well-known/security.txt
security_txt:
  served: true
  url: https://www.peekpro.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain; charset=utf-8
  canonical: https://peekpro.com/.well-known/security.txt
  contact: mailto:security@peek.com
  expires: '2027-05-19T00:00:00.000Z'
  preferred_languages: en
  expired: false
  file: well-known/peek-security.txt
  fields_present: [Contact, Expires, Preferred-Languages, Canonical]
  fields_absent: [Policy, Encryption, Acknowledgments, Hiring, CSAF]
disclosure_channel:
  type: email
  address: security@peek.com
  documented_policy_url: null
bug_bounty:
  program: null
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  found: false
grade: contact-only
notes:
- >-
  Peek publishes a valid, unexpired RFC 9116 security.txt with a dedicated security@peek.com contact — a
  real, machine-discoverable disclosure channel. It carries no Policy: line, so there is no published
  disclosure policy or safe-harbour statement to read, and no bug bounty program was found.
- >-
  The security.txt is served only from the Peek Pro marketing host (www.peekpro.com). peek.com,
  octo.peek.com and octodocs.peek.com all 404 on /.well-known/security.txt, so a researcher who starts at
  the API host or the consumer marketplace will not find it. The Canonical field points at
  peekpro.com/.well-known/security.txt.
x-evidence:
- url: https://www.peekpro.com/.well-known/security.txt
  http_status: 200
  fetched: '2026-08-26'
- url: https://www.peek.com/.well-known/security.txt
  http_status: 404
  fetched: '2026-08-26'
- url: https://octo.peek.com/.well-known/security.txt
  http_status: 404
  fetched: '2026-08-26'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/peek-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.