Spekit · Vulnerability Disclosure

Spekit Vulnerability Disclosure

Vulnerability disclosure

Spekit runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySoftware-as-a-ServiceSales EnablementRevenue EnablementDigital AdoptionKnowledge-ManagementMCPArtificial IntelligenceAnalyticsSalesContent ManagementAgentsAuthentication
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@spekit.co
Contact
infra+security@spekit.co

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.spekit.com/vulnerability-disclosure-program
policy:
- https://www.spekit.com/vulnerability-disclosure-program
contact:
- security@spekit.co
- infra+security@spekit.co
contact_source: >-
  Both addresses are published by Spekit in DNS, as CAA iodef records on spekit.com and
  spekit.co: `0 iodef "mailto:security@spekit.co"` and `0 iodef "mailto:infra+security@spekit.co"`.
  The disclosure page itself takes submissions through a web form rather than an email address.
bug_bounty: false
bug_bounty_note: >-
  No HackerOne, Bugcrowd or Intigriti program was found, and the policy page offers no bounty —
  it is an unpaid coordinated-disclosure program with a submission form.
program:
  name: Spekit Vulnerability Disclosure Policy
  submission: web form on the policy page (email address, location of vulnerability, description, CVSS/score/type, date observed, screenshot upload up to 10MB)
  location_options: [Chrome Browser Extension, Web App, Webpage, IP, Other]
  commitments:
  - Maintain trust and confidentiality with reporting researchers.
  - Work with the reporter to validate and remediate reported vulnerabilities.
  - Investigate and remediate consistent with protecting cloud-customer safety and security.
  - Remediation time varies with severity and affected systems.
  researcher_obligations:
  - Do not disclose submission details without express written permission.
  - Provide clear reproduction steps.
  - Stay inside the scope below.
  - Include an email address so Spekit can follow up.
  out_of_scope:
  - Physical security of offices, employees, equipment
  - Social engineering and phishing
  - DoS/DDoS or any testing that impacts operation of Spekit systems
  - Accessing, downloading or modifying data in an account that is not yours
  - Testing that results in spam or unsolicited messages
  - Testing third-party applications or services
  - Defacing any Spekit asset
  safe_harbor_stated: false
security_txt: false
security_txt_note: >-
  No /.well-known/security.txt is served on any Spekit host (404 on spekit.com,
  www.spekit.com, help.spekit.com and mcp.spekit.co; api.spekit.co and app.spekit.co answer 200
  with an SPA HTML shell, which is not a document). Publishing RFC 9116 security.txt pointing at
  this policy page would make the program machine-discoverable — it is currently only reachable
  by following a footer link from https://www.spekit.com/security.
evidence:
- source: https://www.spekit.com/vulnerability-disclosure-program
  kind: disclosure-policy-page
  http_status: 200
  checked: '2026-08-14'
- source: https://www.spekit.com/security
  kind: referring-page
  http_status: 200
- source: dig CAA spekit.com / spekit.co
  kind: dns-iodef

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/spekit-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.