Redocly · Vulnerability Disclosure

Redocly Vulnerability Disclosure

Vulnerability disclosure

Redocly publishes a full CISA-style vulnerability disclosure policy with a named security contact, an explicit safe-harbour authorization clause, a defined scope list and out-of-scope rules. It is a real programme document, not a boilerplate contact line — but it is NOT discoverable the standard way: /.well-known/security.txt returns 404 on redocly.com, so a scanner following RFC 9116 finds nothing.

Redocly runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Artificial IntelligenceAPI CatalogAPI DocumentationArazzoDeveloper PortalGovernanceLintingMCPMonitoringOpenAPI
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@redocly.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: searched
source: https://redocly.com/vulnerability-disclosure-policy (fetched 2026-08-27, HTTP 200)
provider: Redocly
providerId: redocly
name: Redocly Vulnerability Disclosure Policy
url: https://redocly.com/vulnerability-disclosure-policy
markdown_url: https://redocly.com/vulnerability-disclosure-policy.md
contact: security@redocly.com
description: >-
  Redocly publishes a full CISA-style vulnerability disclosure policy with a
  named security contact, an explicit safe-harbour authorization clause, a
  defined scope list and out-of-scope rules. It is a real programme document,
  not a boilerplate contact line — but it is NOT discoverable the standard
  way: /.well-known/security.txt returns 404 on redocly.com, so a scanner
  following RFC 9116 finds nothing.
program:
  type: vulnerability-disclosure-policy
  bug_bounty: false
  platform: none
  note: >-
    No HackerOne, Bugcrowd or Intigriti programme was found. Reports go
    directly to security@redocly.com.
safe_harbour:
  authorized: true
  text: >-
    Good-faith research in compliance with the policy is considered
    authorized; Redocly will not recommend or pursue legal action, and will
    make the authorization known if a third party initiates action.
scope:
  in_scope:
    - app.redocly.com
    - api.redoc.ly
    - api.redocly.com
    - ssl.redoc.ly
    - ssl.redocly.com
    - app.cloud.redocly.com
    - Redocly Slack App
    - github.com/Redocly (any publicly accessible repository)
  out_of_scope:
    - All other subdomains
    - All customer applications
    - Connected services and vendor systems
  note: >-
    Redocly is hosted on AWS and asks researchers to also comply with AWS
    vulnerability reporting policies.
prohibited_test_methods:
  - Network denial of service (DoS/DDoS) or any test that impairs access or damages a system or data
  - Physical testing, social engineering, phishing, vishing, and other non-technical testing
researcher_obligations:
  - Notify Redocly as soon as possible after discovering a real or potential issue.
  - Avoid privacy violations, UX degradation, production disruption, and destruction or manipulation of data.
  - Use exploits only to the extent needed to confirm the vulnerability; no exfiltration, persistence or pivoting.
  - Allow reasonable time to resolve before public disclosure.
  - Stop testing and notify immediately on encountering sensitive data.
  - Do not submit a high volume of low-quality reports.
gaps:
  - >-
    /.well-known/security.txt returned 404 on redocly.com on 2026-08-27. The
    policy exists but is not machine-discoverable under RFC 9116; adding a
    security.txt with Contact and Policy fields would close this at zero cost.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/redocly-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.