Too Good To Go · Vulnerability Disclosure

Too Good To Go Vulnerability Disclosure

Vulnerability disclosure

Too Good To Go serves an RFC 9116 security.txt naming a single security contact. The file is served identically from the marketing host and from both live API backends. It carries only a Contact field — no Policy, Expires, Encryption, Acknowledgments, Preferred-Languages or Canonical field — so it is a valid but minimal disclosure signal. No public bug bounty program (HackerOne, Bugcrowd, Intigriti) and no standalone responsible-disclosure page were found.

Too Good To Go runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyFood WasteSurplus FoodMarketplaceSustainabilityGrocery RetailConsumer AppClimate TechB CorporationDenmark
Program: Hackerone

Disclosure Policy

Security Contact

Contact
mailto:security@toogoodtogo.com

Source

Vulnerability Disclosure

too-good-to-go-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-30'
method: probed
probe: true
source: https://www.toogoodtogo.com/.well-known/security.txt
description: >-
  Too Good To Go serves an RFC 9116 security.txt naming a single security contact. The file
  is served identically from the marketing host and from both live API backends. It carries
  only a Contact field — no Policy, Expires, Encryption, Acknowledgments, Preferred-Languages
  or Canonical field — so it is a valid but minimal disclosure signal. No public bug bounty
  program (HackerOne, Bugcrowd, Intigriti) and no standalone responsible-disclosure page
  were found.
contact:
- mailto:security@toogoodtogo.com
policy_url: null
bug_bounty:
  present: false
  platform: null
  note: No HackerOne / Bugcrowd / Intigriti program found for toogoodtogo.com.
security_txt:
  file: well-known/too-good-to-go-security.txt
  rfc: RFC 9116
  fields_present:
  - Contact
  fields_missing:
  - Expires
  - Policy
  - Encryption
  - Acknowledgments
  - Preferred-Languages
  - Canonical
  note: >-
    RFC 9116 requires an Expires field; this file omits it, so it is non-conformant to the
    letter of the RFC while still being a real, served, machine-readable contact document.
evidence:
- url: https://www.toogoodtogo.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain; charset=utf-8
- url: https://api.toogoodtogo.com/.well-known/security.txt
  http_status: 200
- url: https://apptoogoodtogo.com/.well-known/security.txt
  http_status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/too-good-to-go-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.