Sift Stack · Vulnerability Disclosure

Sift Stack Vulnerability Disclosure

Vulnerability disclosure

Sift Stack runs a coordinated vulnerability disclosure program on Hackerone.

ObservabilityTelemetryAerospaceDefenseRoboticsTime SeriesSensor DatagRPCData IngestionAnomaly DetectionManufacturingEnergyAutonomous VehiclesMachine DataAgent Ready
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: searched
source: >-
  https://github.com/sift-stack/sift/blob/main/SECURITY.md (present in the repository tarball fetched
  2026-08-27); /.well-known/security.txt probed and 404 on both public hosts.
name: Sift vulnerability disclosure
published: true
channel: repository-security-policy
policy_url: https://github.com/sift-stack/sift/blob/main/SECURITY.md
report_url: https://customer.support.siftstack.com/servicedesk/customer/portal/2/group/2/create/9
security_txt: false
bug_bounty:
  program: false
  platforms_checked: [hackerone, bugcrowd, intigriti]
  note: No bug bounty or coordinated-disclosure program was found.
safe_harbor: false
pgp_key: false
disclosure_policy:
  coordinated: true
  embargo_requested: true
  quote: '"Please take care not to publicize this report as it may put other users at risk."'
verbatim_policy: |
  # SECURITY POLICY

  ## Reporting a Vulnerability

  If you come across security vulnerability please do the following:
  1. Notify the Sift team immediately through the shared Slack channels.
  2. File a bug report at [this link](https://customer.support.siftstack.com/servicedesk/customer/portal/2/group/2/create/9).

  Please take care not to publicize this report as it may put other users at risk.
gaps:
- 'The policy is written for CUSTOMERS, not for the public. Step one is "notify the Sift team immediately through the shared Slack channels" — a channel only an existing customer has. A researcher with no commercial relationship has one usable route, the Jira Service Management portal.'
- 'No /.well-known/security.txt on docs.siftstack.com or www.siftstack.com (both 404), so an automated scanner finds no disclosure route at all — the policy is discoverable only by reading a file in a GitHub repository.'
- 'No security@ address, no PGP key, no safe-harbor statement, no stated response SLA.'
- 'For a vendor holding ITAR-controlled defense telemetry, this is the widest gap in an otherwise strong security posture, and it is cheap to close: a two-line security.txt on both hosts pointing at the existing portal.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/sift-stack-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.