Stensul · Vulnerability Disclosure

Stensul Vulnerability Disclosure

Vulnerability disclosure

Stensul runs a coordinated vulnerability disclosure program on Hackerone.

CompanyEmailEmail MarketingMarketingMarketing AutomationContent ManagementLanding PagesMarketing OperationsEnterprise SoftwareGovernanceCollaborationSoftware-as-a-Service
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

stensul-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-29'
method: probed
source: >-
  Probes of https://stensul.com/.well-known/security.txt,
  https://stensul.com/security-trust-center/, https://trust.stensul.com/, and
  searches of HackerOne, Bugcrowd and Intigriti for a Stensul program, 2026-08-29.
name: Stensul Vulnerability Disclosure
found: false
security_txt:
  url: https://stensul.com/.well-known/security.txt
  status: 404
  note: >-
    Stensul's own apex serves no security.txt. Two subdomains DO serve one, but
    both belong to the hosting SaaS vendor, not to Stensul —
    status.stensul.com returns Atlassian's PGP-signed document (canonical
    www.atlassian.com, contact security@atlassian.com) and helpdesk.stensul.com
    returns Intercom's (canonical app.intercom.com, contact
    security@intercom.com, Bugcrowd disclosure terms). Neither routes a report to
    Stensul, so neither is counted here.
disclosure_policy:
  found: false
  note: >-
    No responsible-disclosure or vulnerability-reporting page was found on
    stensul.com. The public security page (https://stensul.com/security-trust-center/)
    describes controls and the SOC 2 Type 2 audit but names no reporting channel
    or contact for security researchers.
bug_bounty:
  found: false
  platforms_checked:
  - HackerOne
  - Bugcrowd
  - Intigriti
  note: No Stensul program surfaced on any of the three public platforms.
recommendation: >-
  Publishing an RFC 9116 security.txt at https://stensul.com/.well-known/security.txt
  with a Contact and a Policy URL is the single cheapest fix available to Stensul
  here — a researcher who finds an issue today has no published route to report it.
pointer_emitted: false
pointer_note: >-
  No `Security` pointer is wired into apis.yml. The security_disclosure check
  asserts the provider publishes a disclosure channel, and Stensul does not.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/stensul-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.