Pynt · Vulnerability Disclosure

Pynt Vulnerability Disclosure

Vulnerability disclosure

Pynt runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

API TestingAPI SecuritySecurityApplication SecurityDASTAPI DiscoveryVulnerability ManagementPenetration TestingDevSecOpsLLM SecurityMCP SecurityPlatformDeveloper Tools
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
emailsupport@pynt.io
Contact
noteThe disclosure contact is the general support mailbox, not a dedicated security@ address, and no PGP key is published.
Contact
sourceSECURITY.md "Reporting a Vulnerability" and trust-center "Report a vulnerability"

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: searched
source: >-
  https://www.pynt.io/trust-center and
  https://github.com/pynt-io/pynt/blob/main/SECURITY.md
provider: Pynt
providerId: pynt
published: true
program:
  type: vulnerability disclosure policy
  bug_bounty: false
  platform: null
  note: >-
    No HackerOne, Bugcrowd or Intigriti program was found. Pynt runs a
    self-hosted VDP documented as a SECURITY.md in its own public GitHub
    repository and linked from its trust center as "Read our VDP Github Policy".
policy:
  url: https://github.com/pynt-io/pynt/blob/main/SECURITY.md
  raw_url: https://raw.githubusercontent.com/pynt-io/pynt/main/SECURITY.md
  http_status: 200
  fetched: '2026-08-27'
  title: Security and Disclosure Information Policy for Pynt's
contact:
  email: support@pynt.io
  source: SECURITY.md "Reporting a Vulnerability" and trust-center "Report a vulnerability"
  note: >-
    The disclosure contact is the general support mailbox, not a dedicated
    security@ address, and no PGP key is published.
terms:
  acknowledgement_sla: 3 working days
  acknowledgement_sla_source: SECURITY.md "We aim to acknowledge receipt of your report within 3 working days."
  coordinated_disclosure_required: true
  coordinated_disclosure_text: >-
    "Do not disclose the vulnerability publicly or to any third parties before
    it is resolved."
  advisory_commitment: >-
    "Once the vulnerability is resolved, we will provide an advisory to our
    users with details about the issue and the steps taken to address it."
  safe_harbor: not stated
  reward: not stated
announcements:
  channel: Slack community
  url: https://www.pynt.io/community
  source: SECURITY.md "Security Announcements"
  note: >-
    Security announcements are made through the Pynt Slack community channel
    rather than a status page or a security advisories feed. There is no
    status.pynt.io (host does not resolve) and no GitHub Security Advisories
    published on the pynt-io org.
security_txt:
  published: false
  probes:
    - url: https://www.pynt.io/.well-known/security.txt
      status: 404
    - url: https://api.pynt.io/.well-known/security.txt
      status: 404
    - url: https://docs.pynt.io/.well-known/security.txt
      status: 404
  note: >-
    Pynt has a real, findable disclosure policy but does not advertise it at the
    RFC 9116 location. Publishing a /.well-known/security.txt pointing at the
    existing SECURITY.md would make it machine-discoverable for zero additional
    policy work — a notable omission for a company whose product is API
    security.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pynt-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.