StashAway · Vulnerability Disclosure

Stashaway Vulnerability Disclosure

Vulnerability disclosure

StashAway runs a coordinated vulnerability disclosure program on Hackerone.

CompanyWealth ManagementInvestingRobo-AdvisorFinancial-ServicesAsset ManagementETFsCash ManagementFintechSingaporePrivate Markets
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

stashaway-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-29'
method: searched
source: https://www.stashaway.sg/security
note: >-
  StashAway runs a public vulnerability disclosure programme on a dedicated host, but does NOT
  publish an RFC 9116 /.well-known/security.txt on any of its hosts, so the programme is invisible
  to any machine that looks for it at the standard location. The automated probe in
  probe-security-programs.py missed it for exactly that reason; it was found by reading the
  human-facing security page. Publishing a security.txt with `Policy: https://vdp.stashaway.com/`
  would make an already-existing programme machine-discoverable at zero cost.
program:
  present: true
  name: StashAway Vulnerability Disclosure Policy
  url: https://vdp.stashaway.com/
  hosted_on: vdp.stashaway.com (first-party subdomain, Quasar single-page app)
  platform: self-hosted (no HackerOne, Bugcrowd or Intigriti listing found)
  bug_bounty: unknown
  safe_harbor_stated: >-
    The public security page authorises reporting but states that "attempts to exploit" a
    vulnerability are prohibited. The full policy text is rendered client-side on
    vdp.stashaway.com and was not readable from the served HTML.
security_txt:
  present: false
  probed:
  - url: https://www.stashaway.sg/.well-known/security.txt
    status: 404
  - url: https://www.stashaway.my/.well-known/security.txt
    status: 404
  - url: https://www.stashaway.ae/.well-known/security.txt
    status: 404
  - url: https://www.stashaway.hk/.well-known/security.txt
    status: 404
evidence:
- url: https://www.stashaway.sg/security
  status: 200
  kind: disclosure pointer
  detail: >-
    Served HTML contains the literal string "vdp.stashaway.com/" three times, in the sentence
    "You can find more information on how to report here."
- url: https://vdp.stashaway.com/
  status: 200
  kind: disclosure portal
  content_type: text/html; charset=utf-8
  detail: >-
    Live host. The served body is a 2,087-byte single-page-app shell whose
    <meta name="description"> is "Vulnerability Disclosure Policy" and whose <title> is "VDP";
    the policy itself renders client-side and was not read.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/stashaway-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.