Secton API · Vulnerability Disclosure

Secton Api Vulnerability Disclosure

Vulnerability disclosure

Secton API runs a coordinated vulnerability disclosure program on Hackerone.

Artificial IntelligenceInferenceLLMChat CompletionsGenerative AIDeveloper ToolsOpenAI-CompatibleStreamingMachine-Learning
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-16'
method: searched
source: https://secton.org/security
program:
  exists: true
  name: Secton Security — responsible disclosure
  page: https://secton.org/security
  page_status: 200
  intake: hackerone-embedded-submission-form
  intake_url: https://hackerone.com/b69c37c0-6094-417e-a729-e009b003adc3/embedded_submissions/new?locale=en
  scope_statement: >-
    "If you discover a vulnerability in any of our products, services, or infrastructure, please
    report it responsibly through our HackerOne submission form."
  bounty: false
  bounty_statement: >-
    "We do not offer monetary bounties or rewards. Reports are made on a voluntary basis and are
    deeply appreciated as a contribution to public safety, privacy, and open collaboration."
  safe_harbor_published: false
  response_sla_published: false
  pgp_key_published: false
security_txt:
  served: false
  probed:
    - url: https://secton.org/.well-known/security.txt
      status: 404
    - url: https://console.secton.org/.well-known/security.txt
      status: 404
    - url: https://api.secton.org/.well-known/security.txt
      status: 200
      note: soft-404 — body is `{"message":"The /.well-known/security.txt endpoint doesn't exist!"}`
  gap: >-
    A real disclosure program exists but is not machine-discoverable. RFC 9116 security.txt at
    secton.org/.well-known/security.txt with `Contact:` pointing at the HackerOne form and a
    `Policy:` pointing at https://secton.org/security would close this.
track_record:
  - date: '2025-10-07'
    url: https://secton.org/blog/addressing-what-happened-back-in-june
    title: Addressing What Happened Back in June
    summary: >-
      Public post-incident write-up of three vulnerabilities reported to Secton on 2025-06-23 and
      remediated within 24 hours (by 2025-06-24): a client-side-only rate limit on Copilot guest
      messages that could be bypassed from browser DevTools; a hardcoded public "playground" token
      that granted unlimited access to the chat-completion endpoint; and an unauthenticated
      ai-compute.secton.org endpoint. Secton states there is no evidence of exploitation in the
      wild, and that the generic token was revoked and server-side authentication enforced.
    note: >-
      Recorded because it is first-party evidence that the program actually processes reports and
      publishes outcomes — rarer than a disclosure page. It is also the reason the disclosure page
      exists: the write-up ends by directing future reports through formal channels.
      (The ai-compute.secton.org host no longer resolves as of this pass.)
contacts:
  - purpose: general / product support
    value: https://secton.org/contact
  - purpose: general (site-wide footer)
    value: management@secton.org
  - purpose: legal
    value: legal@secton.org
  - purpose: press
    value: press@secton.org
contacts_source: >-
    Decoded from the Cloudflare email-protection payloads on https://secton.org/,
    https://secton.org/contact and https://secton.org/security — these are the addresses the pages
    render to a browser, not inferred ones.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/secton-api-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.