Phosphorus · Vulnerability Disclosure

Phosphorus Vulnerability Disclosure

Vulnerability disclosure

Phosphorus runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CybersecurityxIoT SecurityIoT SecurityOT SecurityIoMTAsset DiscoveryVulnerability ManagementFirmware ManagementCertificate ManagementCredential ManagementCritical InfrastructureDevice Management
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emailsecurity@phosphorus.io
Contact
key_published2017-06-12
Contact
pgp_key_rawhttps://raw.githubusercontent.com/phosphorusinc/public/master/security@phosphorus.io.asc
Contact
pgp_key_sourceKeybase OpenPGP v2.0.71 -- https://keybase.io/phosphorusinc
Contact
pgp_key_urlhttps://github.com/phosphorusinc/public/blob/master/security%40phosphorus.io.asc

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-26'
method: searched
source: https://github.com/phosphorusinc/public
note: >-
  Phosphorus publishes a dedicated security contact and a PGP public key for it, in its own public
  GitHub organization -- the only vulnerability-reporting channel it publishes anywhere. It is thin
  and old, and that is recorded here rather than dressed up: the repository was last pushed on
  2017-06-12, there is no disclosure policy, no safe-harbour statement, no scope definition, no
  response-time commitment, and no bug bounty. RFC 9116 is not served: /.well-known/security.txt
  returns 404 on phosphorus.io and on every other Phosphorus host probed. The key file itself is
  deliberately NOT copied into this repository -- it is linked, so the provider's own copy stays the
  source of truth.
published: true
program_type: security-contact
contact:
  email: security@phosphorus.io
  pgp_key_url: https://github.com/phosphorusinc/public/blob/master/security%40phosphorus.io.asc
  pgp_key_raw: https://raw.githubusercontent.com/phosphorusinc/public/master/security@phosphorus.io.asc
  pgp_key_source: Keybase OpenPGP v2.0.71 -- https://keybase.io/phosphorusinc
  key_published: '2017-06-12'
policy_url: null
safe_harbour: false
scope_defined: false
response_commitment: null
bug_bounty:
  program: none
  platforms_checked:
  - hackerone
  - bugcrowd
  - intigriti
  found: false
security_txt:
  served: false
  evidence:
  - url: https://phosphorus.io/.well-known/security.txt
    status: 404
  - url: https://api.phosphorus.io/.well-known/security.txt
    status: 503
  - url: https://docs.phosphorus.io/.well-known/security.txt
    status: 403
  - url: https://support.phosphorus.io/.well-known/security.txt
    status: 404
evidence:
- url: https://github.com/phosphorusinc/public
  status: 200
  finding: repository contains README.md and security@phosphorus.io.asc
- url: https://raw.githubusercontent.com/phosphorusinc/public/master/security@phosphorus.io.asc
  status: 200
  finding: 4,704-byte PGP PUBLIC KEY BLOCK, Keybase-generated, for security@phosphorus.io

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/phosphorus-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.