Posh · Vulnerability Disclosure

Posh Vulnerability Disclosure

Vulnerability disclosure

Posh runs a coordinated vulnerability disclosure program on Hackerone.

Artificial IntelligenceConversational AIAgentic AIBankingCredit UnionsFinancial-ServicesCustomer ServiceContact CenterVoiceChatbotsKnowledge-ManagementRegTech
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

posh-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-26'
method: searched
source: https://security.posh.ai/item/responsible-disclosure-policy
program_type: responsible-disclosure-policy
bug_bounty: false
bug_bounty_platform: null
policy_url: https://security.posh.ai/item/responsible-disclosure-policy
contact: null
security_txt: false
note: >-
  Posh publishes a named Responsible Disclosure Policy as an item inside its SafeBase trust
  center. The trust center states verbatim: "To report a potential security issue, please follow
  the guidelines in our Responsible Disclosure Policy." No RFC 9116 /.well-known/security.txt is
  served on any Posh host (all probed 404/403), and no public bug-bounty program was found on
  HackerOne, Bugcrowd or Intigriti. The policy item itself returns HTTP 403 to a command-line
  agent — the SafeBase bot challenge — so the reporting email, scope and safe-harbor terms could
  not be read in this pass and are recorded as unknown rather than guessed.
gaps:
  - no /.well-known/security.txt on www.posh.ai, api.poshdevelopment.com or app.poshdevelopment.com
  - policy body not machine-readable (JS-rendered SafeBase portal, 403 to non-browser agents)
  - no published reporting address outside the gated policy document
evidence:
  - url: https://security.posh.ai/item/responsible-disclosure-policy
    status: 403
  - url: https://security.posh.ai/
    status: 403
  - url: https://www.posh.ai/.well-known/security.txt
    status: 404
  - url: https://api.poshdevelopment.com/.well-known/security.txt
    status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/posh-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.