Solvela · Vulnerability Disclosure

Solvela Ai Vulnerability Disclosure

Vulnerability disclosure

Solvela runs a coordinated vulnerability disclosure program on Hackerone.

CompanyPaymentsArtificial IntelligenceLLM Gatewayx402SolanaStablecoinsAI AgentsMCPA2AAgentic Commerce
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
source: https://github.com/solvela-ai/solvela/blob/main/SECURITY.md
probed:
- {url: 'https://github.com/solvela-ai/solvela/blob/main/SECURITY.md', status: 200, fetched: '2026-09-19'}
- {url: 'https://api.solvela.ai/.well-known/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://api.solvela.ai/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://solvela-gateway.fly.dev/.well-known/security.txt', status: 404, fetched: '2026-09-19'}
- {url: 'https://solvela.ai/.well-known/security.txt', status: 402, fetched: '2026-09-19', note: Vercel DEPLOYMENT_DISABLED}
summary: >-
  Solvela publishes a vulnerability disclosure policy as SECURITY.md in its public repository: report to
  security@solvela.ai, do not open public issues, acknowledgement within 1 hour for P0 (custody, payment, auth)
  and a response within 24 hours for everything else. The same file states that an RFC 9116 security.txt "is
  served from api.solvela.ai"; it is not — both well-known paths 404 on both API hosts as of 2026-09-19 — so the
  policy is findable through GitHub but not through the standard machine path. No bug bounty programme
  (HackerOne, Bugcrowd, Intigriti or self-run) was found, no safe-harbour language, no PGP key and no
  encrypted channel. The file goes unusually far in disclosing posture: the escrow program's upgrade authority
  (a warm single-sig key with a planned Squads multisig migration), the unified fee-payer/recipient wallet, the
  accepted transitive advisories with reasons, and the semantic-cache embedding caveat. probe-security-programs.py
  found no hit because it looks for security.txt, bounty platforms and disclosure pages on the provider's hosts;
  this file upgrades that result from the repository.
policy:
  url: https://github.com/solvela-ai/solvela/blob/main/SECURITY.md
  contact: security@solvela.ai
  contact_type: email
  public_issues: discouraged — "Do not open public GitHub issues for security reports"
  acknowledgement: 1 hour for P0 (custody / payment / auth)
  response: 24 hours for everything else
  scope: gateway (api.solvela.ai), dashboard (solvela.ai, app.solvela.ai, docs.solvela.ai), escrow program on Solana mainnet, SDKs
  safe_harbor: not stated
  pgp: none published
  bug_bounty: none found
  security_txt:
    claimed: true
    served: false
    note: '"A .well-known/security.txt is served from api.solvela.ai" (SECURITY.md) — 404 on 2026-09-19.'
disclosed_posture:
  escrow_program: '9neDHouXgEgHZDde5SpmqqEZ9Uv35hFcjtFEPxomtHLU on Solana mainnet; upgrade authority EDM9pao5miQdJYfzCtZii9cVn5ZHTBJq84Y9yyqZbsr4, single-sig on the operator workstation (migrated 2026-05-08 off the gateway hot wallet); Squads multisig or hardware-backed authority is the stated next step'
  operational_wallet: '9QGtTUpvLmhggDuBciAeE67MmhECVFYdFLD7xKD4RSno serves as both fee payer and payment recipient by design (consolidated 2026-05-29 to 05-31)'
  dependency_hygiene: cargo audit and npm audit pass at HEAD; a short list of accepted transitive advisories is published with reasons
  runtime_controls: [ed25519 signature + ATA + TransferChecked verification, replay protection (Redis SET NX EX 120), prompt-injection/jailbreak/PII guard run before any funds move, per-wallet rate limiting that ignores X-Forwarded-For, explicit CORS allowlist, secret redaction in Debug impls, SSRF checks on marketplace endpoints, constant-time admin-token comparison]
  data_minimisation: 'no prompt or response content is persisted; IPs only in transient rate-limit buckets and the admin audit trail (docs/product/regulatory-position.md)'
  a2a_task_ids: documented as bearer capabilities with a 10-minute TTL

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/solvela-ai-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.