Superscale · Vulnerability Disclosure

Superscale Vulnerability Disclosure

Vulnerability disclosure

Superscale runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyArtificial IntelligenceMarketingAdvertisingGenerative AICreativeAdTechSoftware-as-a-ServiceAgentsMCPA2AAgent SkillsAdvertising TechnologyVideo GenerationMedia Buying
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@superscale.ai

Source

Vulnerability Disclosure

superscale-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-12'
method: searched
probe: true
source: https://superscale.ai/.well-known/security.txt
contact:
- mailto:security@superscale.ai
policy: []
policy_note: >-
  No Policy: field, no responsible-disclosure page and no bug bounty program.
  Probed /security, /responsible-disclosure, /vulnerability-disclosure and
  /security/responsible-disclosure on superscale.ai — all return the Next.js SPA
  shell rather than a disclosure document. No HackerOne, Bugcrowd or Intigriti
  program was found.
security_txt:
  url: https://superscale.ai/.well-known/security.txt
  http_status: 200
  content_type: text/plain
  also_served_from: https://app.superscale.ai/.well-known/security.txt
  fields:
    contact: mailto:security@superscale.ai
    expires: '2026-08-08T23:59:00.000Z'
    preferred_languages: en,de
  expired: true
  expired_note: >-
    The document expired on 2026-08-08, four days before this probe on
    2026-08-12. RFC 9116 section 2.5.5 says a security.txt whose Expires date
    has passed should not be relied upon — a finder acting correctly would treat
    the contact as stale. Refreshing the Expires field is a one-line fix.
  missing_recommended_fields: [Policy, Encryption, Acknowledgments, Canonical, Hiring]
evidence:
- source: https://superscale.ai/.well-known/security.txt
  kind: security.txt (live probe)
  http_status: 200
  fetched: '2026-08-12'
- source: https://app.superscale.ai/.well-known/security.txt
  kind: security.txt (live probe, identical body)
  http_status: 200
  fetched: '2026-08-12'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/superscale-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.