Spate · Vulnerability Disclosure

Spate Vulnerability Disclosure

Vulnerability disclosure

Spate runs a coordinated vulnerability disclosure program on Hackerone.

CompanyEnterprise SaasMarket IntelligenceTrend ForecastingConsumer InsightsSocial ListeningAnalyticsBeautyMCPAI AgentsTrend DataConsumer Packaged Goods
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

spate-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.spate.nyc/security-at-spate
note: >-
  Spate publishes a dedicated security contact address on its own security
  page, which is a real, reachable disclosure channel. It does NOT publish a
  vulnerability disclosure policy, safe-harbour language, scope, response
  commitments, or a bug bounty, and it serves no RFC 9116 security.txt on any
  host. Recorded honestly as "contact only".

disclosure:
  published_policy: false
  contact_published: true
  contact: security@spate.nyc
  contact_source: https://www.spate.nyc/security-at-spate
  contact_quote: >-
    "For further inquiries or information, please contact security@spate.nyc."
  policy_url: null
  safe_harbor: false
  scope_defined: false
  response_sla: null
  preferred_languages: null

bug_bounty:
  program: false
  platform: null
  checked:
  - hackerone.com
  - bugcrowd.com
  - intigriti.com
  result: no Spate program found on any of the three major platforms

security_txt:
  served: false
  probes:
  - url: https://www.spate.nyc/.well-known/security.txt
    status: 404
  - url: https://spate.nyc/.well-known/security.txt
    status: 404
  - url: https://api.spate.nyc/.well-known/security.txt
    status: 404
  - url: https://www.spate.nyc/security.txt
    status: 404
  - url: https://app.spate.nyc/.well-known/security.txt
    status: 200
    document: false
    note: SPA HTML shell, soft-404 — not a security.txt.

supporting_practices:
  source: https://www.spate.nyc/security-at-spate
  claims:
  - Automated vulnerability scanning and detection of infrastructure and codebase
  - Penetration testing at least once annually
  - Documented incident response with detailed logging and post-incident review

recommendation: >-
  Publishing an RFC 9116 /.well-known/security.txt pointing at
  security@spate.nyc, plus a short disclosure policy with scope and
  safe-harbour, would turn an existing mailbox into a discoverable,
  machine-readable disclosure channel at essentially zero cost.