Stoplight · Vulnerability Disclosure

Stoplight Vulnerability Disclosure

Vulnerability disclosure

Vulnerability disclosure posture for Stoplight. Stoplight itself publishes a security-practices page but no intake channel; the working disclosure channel is the parent company's. Stoplight has been a SmartBear product since the 2023 acquisition, and stoplight.status.smartbear.com plus the SmartBear-hosted community confirm the same operational consolidation applies to security.

Stoplight runs a coordinated vulnerability disclosure program on Hackerone.

API DesignAPI DocumentationAPI GovernanceAsyncAPIDesign-FirstLintingMock ServersOpenAPISmartBear API HubStyle Guides
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: searched
source: https://smartbear.com/security/
provider: Stoplight
providerId: stoplight
description: >-
  Vulnerability disclosure posture for Stoplight. Stoplight itself publishes a
  security-practices page but no intake channel; the working disclosure channel is
  the parent company's. Stoplight has been a SmartBear product since the 2023
  acquisition, and stoplight.status.smartbear.com plus the SmartBear-hosted community
  confirm the same operational consolidation applies to security.
program:
  published: true
  operator: SmartBear
  intake_url: https://smartbear.com/security/
  intake_status: 200
  intake_probed: '2026-08-27'
  intake_mechanism: >-
    "Submit a vulnerability" form, opened from a modal on the SmartBear security page
    (element id `open-vuln-modal`, dialog labelled "Submit Vulnerability Report").
  bug_bounty: false
  bug_bounty_platform: null
  note: >-
    No HackerOne, Bugcrowd or Intigriti program was found for Stoplight or SmartBear.
    The disclosure channel is a first-party web form, not a bounty.
stoplight_own_page:
  url: https://stoplight.io/security-practices
  status: 200
  probed: '2026-08-27'
  note: >-
    Describes Stoplight's security practices. It is a posture page, not a disclosure
    channel — it names no security contact address and no reporting process.
security_txt:
  served: false
  probed_paths:
    - url: https://stoplight.io/.well-known/security.txt
      status: 404
    - url: https://docs.stoplight.io/.well-known/security.txt
      status: 404
    - url: https://smartbear.com/.well-known/security.txt
      status: 404
  note: >-
    No RFC 9116 security.txt on any Stoplight or SmartBear host. See
    well-known/stoplight-well-known.yml for the full probe.
repository_policy:
  published: false
  probed:
    - url: https://api.github.com/repos/stoplightio/.github/contents/SECURITY.md
      status: 404
    - url: https://api.github.com/repos/stoplightio/spectral/contents/SECURITY.md
      status: 404
    - url: https://api.github.com/repos/stoplightio/prism/contents/SECURITY.md
      status: 404
  note: >-
    None of the flagship open-source repos carries a SECURITY.md, and the org-level
    stoplightio/.github template repo does not supply one either.
gaps:
  - No security.txt on any host.
  - No SECURITY.md on the open-source repos that carry the largest install base.
  - No published disclosure SLA, safe-harbour statement or PGP key.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/stoplight-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.