ShieldLabs · Vulnerability Disclosure

Shieldlabs Vulnerability Disclosure

Vulnerability disclosure

ShieldLabs runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Fraud PreventionAbuse PreventionVisitor IdentificationDevice FingerprintingBot Detectionvpn-proxy-detectionRisk ScoringIdentitySecurityWebhooktraffic-qualityA2A
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
contact@shieldlabs.ai

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-04'
method: searched
probe: true
source: https://docs.shieldlabs.ai/security
note: >-
  ShieldLabs publishes a short but genuine responsible-disclosure statement in its docs, with a named
  contact and a good-faith safe-harbour sentence. What it does not have: an RFC 9116 security.txt on
  any host (probed all five, all 404), a bug bounty program on HackerOne, Bugcrowd or Intigriti, a
  dedicated /security policy page on the marketing site, a PGP key, or a stated response SLA. The
  single security address is the same generic contact@shieldlabs.ai used for sales, privacy and
  support, so a report has no separate intake path.

  Re-checked 2026-09-04 across eight hosts rather than five, with the CDN, dashboard and ingest hosts
  added. Nothing changed: still no security.txt anywhere, still no bug bounty, still one generic
  address. The disclosure page itself is unchanged and still returns 200. The deterministic probe
  script was re-run this round and produced a thinner file than this one; this hand-verified version
  was kept, per the rule that a stronger artifact is never replaced by a weaker one.
policy:
- https://docs.shieldlabs.ai/security
contact:
- contact@shieldlabs.ai
policy_text: >-
  "If you find a security issue in ShieldLabs, report it privately to contact@shieldlabs.ai. Please
  include enough detail to reproduce it, and give us a reasonable window to confirm and fix before any
  public disclosure. We do not pursue good-faith researchers who follow coordinated disclosure."
safe_harbour: true
bug_bounty: false
bug_bounty_programs: []
security_txt: false
security_txt_probes:
- {url: 'https://shieldlabs.ai/.well-known/security.txt', status: 404}
- {url: 'https://www.shieldlabs.ai/.well-known/security.txt', status: 404}
- {url: 'https://docs.shieldlabs.ai/.well-known/security.txt', status: 404}
- {url: 'https://api.shieldlabs.ai/.well-known/security.txt', status: 404}
- {url: 'https://account.shieldlabs.ai/.well-known/security.txt', status: 404}
- {url: 'https://cdn.shieldlabs.ai/.well-known/security.txt', status: 404}
- {url: 'https://rest.shieldlabs.ai/.well-known/security.txt', status: 404}
- {url: 'https://app.shieldlabs.ai/.well-known/security.txt', status: 200, verdict: 'soft-200 SPA catch-all — the same 1,512-byte HTML shell is returned for a negative-control path that cannot exist, so this is not a document'}
security_txt_recheck: '2026-09-04'
response_sla: null
pgp_key: null
evidence:
- source: https://docs.shieldlabs.ai/security
  kind: disclosure page
  http_status: 200
  keywords:
  - responsible disclosure
  - coordinated disclosure
  - security issue
  - report it privately
- source: https://docs.shieldlabs.ai/support
  kind: support page naming a security contact
  http_status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/shieldlabs-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.