Redocly · Vulnerability Disclosure
Redocly Vulnerability Disclosure
Vulnerability disclosure
Redocly publishes a full CISA-style vulnerability disclosure policy with a named security contact, an explicit safe-harbour authorization clause, a defined scope list and out-of-scope rules. It is a real programme document, not a boilerplate contact line — but it is NOT discoverable the standard way: /.well-known/security.txt returns 404 on redocly.com, so a scanner following RFC 9116 finds nothing.
Redocly runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
Artificial IntelligenceAPI CatalogAPI DocumentationArazzoDeveloper PortalGovernanceLintingMCPMonitoringOpenAPI
Program: Hackerone
Disclosure Policy
Security Contact
Contact
security@redocly.com
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.