Taulia · Vulnerability Disclosure

Taulia Vulnerability Disclosure

Vulnerability disclosure

Taulia runs a coordinated vulnerability disclosure program on Hackerone.

CompanyWorking CapitalSupply Chain FinanceDynamic DiscountingAccounts PayableAccounts ReceivableInvoicingPaymentsProcurementFinancial-ServicesERP IntegrationSAP
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

taulia-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-29'
method: searched
source: https://taulia.com/.well-known/security.txt
program:
  present: true
  type: security-contact
  security_txt:
    url: https://taulia.com/.well-known/security.txt
    status: 200
    canonical: https://taulia.com/.well-known/security.txt
    contact: mailto:bug-bounty@taulia.com
    expires: '2026-12-31T00:00:00.000Z'
    fields_present:
    - Canonical
    - Contact
    - Expires
    fields_absent:
    - Policy
    - Encryption
    - Acknowledgments
    - Preferred-Languages
    - Hiring
  bug_bounty:
    mailbox: bug-bounty@taulia.com
    platform: null
    note: >-
      The security.txt Contact is a mailbox literally named bug-bounty@taulia.com, which is the
      only public evidence of a bounty programme. No HackerOne, Bugcrowd or Intigriti listing was
      found for SAP Taulia, and no disclosure policy URL is published — the security.txt carries no
      Policy field.
  disclosure_policy_url: null
supporting_pages:
- url: https://taulia.com/company/why-taulia/commitment-to-security/
  status: 200
  title: Commitment to Security
  note: >-
    Describes SSAE SOC 1 Type 2 auditing, daily third-party PCI-approved website scanning, SSL,
    two-factor authentication and adaptive lockout. It does not name a vulnerability disclosure
    process.
- url: https://taulia.com/sap-taulia-agreements/
  status: 200
  title: Agreements, Data Protection and Privacy
  note: >-
    Links the Security Measures for Cloud Services, Taulia Platform Data Security Standard Policy,
    Data Processing Agreement, Personal Data Sub-Processors and Export Control and Sanctions
    Compliance Notice documents.
gaps:
- No Policy field in security.txt — a reporter has a mailbox but no published safe-harbour terms.
- No public bounty-platform listing, scope statement, or response SLA.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/taulia-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.