Tradeshift · Vulnerability Disclosure

Tradeshift Vulnerability Disclosure

Vulnerability disclosure

Tradeshift runs a coordinated vulnerability disclosure program on Hackerone.

e-invoicingaccounts-payableap-automationprocure-to-paysupply-chainb2b-commerceinvoicingublpeppole-invoicing-compliancesupplier-networkbusiness-documentsfintechmcpagent-native
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-02'
method: probed
probe: true
program: none-published
source: https://tradeshift.com/security/
summary: >-
  Tradeshift publishes a security policy page describing its vulnerability management practice, but NOT a
  vulnerability disclosure programme. No security.txt on any host, no security@ or PSIRT contact published, and no
  bug-bounty programme found on HackerOne, Bugcrowd or Intigriti. The automated probe's initial hit on
  https://tradeshift.com/security/ was a keyword match on the "Vulnerability Management and Incident Response"
  section of the security whitepaper, not a disclosure channel; it is recorded here honestly rather than counted as a
  programme.
policy: []
contact: []
bug_bounty: null
security_policy_page: https://tradeshift.com/security/
published_practice:
  - Regular vulnerability scanning and penetration testing.
  - A defined incident response plan covering identify, contain, eradicate and recover.
  - Regular mock incident-response tests.
  - Source code reviewed and scanned for security issues before and after release.
  - Periodic scanning for out-of-date software, libraries and misconfiguration.
probes:
  - url: https://tradeshift.com/.well-known/security.txt
    http_status: 404
  - url: https://api.tradeshift.com/.well-known/security.txt
    http_status: 405
  - url: https://developers.tradeshift.com/.well-known/security.txt
    http_status: 200
    rejected: true
    reason: SPA catch-all HTML shell, not a security.txt
  - url: https://mcp.tradeshift.com/.well-known/security.txt
    http_status: 401
  - url: https://tradeshift.com/responsible-disclosure/
    http_status: 404
  - url: https://tradeshift.com/vulnerability-disclosure/
    http_status: 404
  - url: https://hackerone.com/tradeshift
    http_status: 404
evidence:
  - source: https://tradeshift.com/security/
    kind: security policy page
    keywords: [vulnerability management, incident response, penetration tests]
gap:
  - No RFC 9116 security.txt on any Tradeshift host.
  - No published disclosure contact or coordinated-disclosure policy.
  - No public bug bounty programme.
x-evidence:
  fetched: '2026-08-02'