SignSealShip Partner API · Vulnerability Disclosure

Signsealship Vulnerability Disclosure

Vulnerability disclosure

SignSealShip Partner API runs a coordinated vulnerability disclosure program on Hackerone.

notarizationremote online notarizationelectronic signaturedocument verificationlegal technologyreal estatetitle and escrowshipping
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-01'
method: searched
source: https://signsealship.com/security
docs: https://signsealship.com/security
program:
  published: true
  type: direct-email responsible disclosure
  contact: security@signsealship.com
  contact_method: email
  policy_url: https://signsealship.com/security
  policy_section: RESPONSIBLE DISCLOSURE
  probed: '2026-09-01'
  http_status: 200
safe_harbor:
  stated: true
  wording: >-
    "A human reads every report, we'll acknowledge yours, and we won't pursue action against
    good-faith security research."
acknowledgement: >-
  Committed -- "we'll acknowledge yours". No SLA on time-to-acknowledge is published.
submission_requirements:
  - Steps to reproduce, where the reporter can supply them.
bug_bounty:
  present: false
  platform: none
  note: >-
    No HackerOne, Bugcrowd or Intigriti program was found. No monetary reward is offered or
    implied.
security_txt:
  present: false
  probed_urls:
  - url: https://signsealship.com/.well-known/security.txt
    status: 404
  - url: https://docs.signsealship.com/.well-known/security.txt
    status: 404
  gap: >-
    THE PROGRAM EXISTS BUT IS NOT MACHINE-DISCOVERABLE. A researcher's or scanner's first stop is
    /.well-known/security.txt, which 404s on both hosts; the address and the safe-harbor
    statement live only in prose on an HTML page. A four-line RFC 9116 file naming Contact:
    mailto:security@signsealship.com, Policy: https://signsealship.com/security and an Expires
    date would make an already-real program findable, and is the cheapest security improvement
    available to this provider.
disclosure_posture_note: >-
  Framed by the provider as "No forms, no gatekeeping." Deliberately low-friction, which is a
  reasonable posture for a company of this size -- the gap is discoverability, not intent.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/signsealship-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.