Stannp · Vulnerability Disclosure

Stannp Vulnerability Disclosure

Vulnerability disclosure

Stannp runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Direct MailPostcardsLettersPrintPhysical MailMarketing AutomationCampaignsAddress VerificationSMSWebhookMailing ListsFulfillment
Program: Hackerone

Disclosure Policy

Security Contact

Contact
{"kind" => "web-form", "owner_role" => "Compliance Team", "stated_purpose" => "\"...or need to report a security issue, complete the form and we'll respond promptly.\"", "url" => "https://www.stannp.com/us/trust"}
Contact
{"address" => "support.us@stannp.com", "kind" => "email", "note" => "General support address published in the site footer. Not designated for security reports; recorded because it is the only published email channel."}

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.stannp.com/us/trust
grade: minimal
summary: >-
  Stannp publishes a named intake channel for reporting a security issue — the
  Compliance Team form on its trust center — and nothing more. There is no
  security.txt, no dedicated /security or /responsible-disclosure page, no bug
  bounty, no safe-harbour statement, no PGP key and no published response SLA
  for security reports. Recorded as a real but minimal disclosure posture, with
  the gaps named rather than implied.
policy: []
policy_url: null
contact:
  - kind: web-form
    url: https://www.stannp.com/us/trust
    owner_role: Compliance Team
    stated_purpose: >-
      "...or need to report a security issue, complete the form and we'll
      respond promptly."
  - kind: email
    address: support.us@stannp.com
    note: >-
      General support address published in the site footer. Not designated for
      security reports; recorded because it is the only published email channel.
bug_bounty:
  program: none
  platforms_checked:
    - HackerOne
    - Bugcrowd
    - Intigriti
  result: no program found
security_txt:
  served: false
  probed:
    - url: https://www.stannp.com/.well-known/security.txt
      status: 200
      served: false
      reason: >-
        Soft-200 catch-all — body is `{}`, and a nonsense control path
        (/.well-known/this-does-not-exist-xyz) returns the identical 200 + `{}`.
        Not a served RFC 9116 document.
    - url: https://api-eu1.stannp.com/.well-known/security.txt
      status: 404
    - url: https://api-us1.stannp.com/.well-known/security.txt
      status: 404
    - url: https://app-us1.stannp.com/.well-known/security.txt
      status: 200
      served: false
      reason: Soft-200 SPA catch-all — body is an HTML shell.
  see_also: well-known/stannp-well-known.yml
disclosure_pages_probed:
  - url: https://www.stannp.com/us/security
    status: 404
  - url: https://www.stannp.com/us/direct-mail-api/changelog
    status: 404
    note: probed while looking for a security advisories feed
security_practices_published:
  source: https://www.stannp.com/us/developer-tools
  claims:
    - weekly penetration testing
    - two-factor authentication
    - SFTP for all off-platform data exchange
    - SecurityScorecard A rating
    - GDPR and ISO 9001/27001 compliance
    - Royal Mail Mail Made Easy certification
evidence:
  - source: https://www.stannp.com/us/trust
    kind: trust-center security contact
    status: 200
  - source: https://www.stannp.com/us/developer-tools
    kind: published security practices
    status: 200
gaps:
  - No /.well-known/security.txt (RFC 9116).
  - No standalone vulnerability disclosure or responsible disclosure policy page.
  - No safe-harbour / non-prosecution statement for good-faith researchers.
  - No PGP/OpenPGP key or encrypted intake.
  - No published acknowledgement or remediation timeline for security reports.
  - No CVE/advisory feed.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/stannp-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.