Thinking Machines · Vulnerability Disclosure

Thinking Machines Vulnerability Disclosure

Vulnerability disclosure

Thinking Machines Lab publishes a Coordinated Vulnerability Disclosure Policy and a security.txt. It operates a coordinated-disclosure program with an explicit safe harbor, but no paid bug bounty.

Thinking Machines publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyArtificial IntelligenceMachine-LearningFine-TuningLLMModel TrainingDeveloper Tools
Program:

Disclosure Policy

Security Contact

Contact
security-reports@thinkingmachines.ai

Source

Vulnerability Disclosure

thinking-machines-vulnerability-disclosure.yml Raw ↑
generated: 2026-07-21
method: searched
source: >-
  https://thinkingmachines.ai/security/disclosure-policy/ +
  https://thinkingmachines.ai/.well-known/security.txt
name: Thinking Machines vulnerability disclosure
description: >-
  Thinking Machines Lab publishes a Coordinated Vulnerability Disclosure Policy
  and a security.txt. It operates a coordinated-disclosure program with an
  explicit safe harbor, but no paid bug bounty.
program:
  type: coordinated-disclosure
  bug_bounty: false
  bounty_note: >-
    "We do not operate a bug bounty program and do not offer monetary rewards or
    compensation of any kind for vulnerability reports."
policy_url: https://thinkingmachines.ai/security/disclosure-policy/
security_txt:
  url: https://thinkingmachines.ai/.well-known/security.txt
  contact: mailto:security-reports@thinkingmachines.ai
  encryption: https://thinkingmachines.ai/.well-known/pgp-key.txt
  expires: '2029-07-13T07:00:00.000Z'
safe_harbor: true
safe_harbor_note: >-
  Good-faith research conducted in compliance with the policy is considered
  authorized; the company will not pursue legal action under the CFAA or DMCA
  anti-circumvention provisions and will waive conflicting ToS/AUP restrictions
  to the extent necessary for disclosure.
contact: security-reports@thinkingmachines.ai

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/thinking-machines-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.