Tradeshift · Vulnerability Disclosure

Tradeshift Vulnerability Disclosure

Vulnerability disclosure

Tradeshift runs a coordinated vulnerability disclosure program on Hackerone.

E-InvoicingAccounts PayableAP AutomationProcure-to-PaySupply ChainB2B CommerceInvoicingublPEPPOLe-invoicing-complianceSupplier Networkbusiness-documentsFintechMCPagent-native
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-02'
method: probed
probe: true
program: none-published
source: https://tradeshift.com/security/
summary: >-
  Tradeshift publishes a security policy page describing its vulnerability management practice, but NOT a
  vulnerability disclosure programme. No security.txt on any host, no security@ or PSIRT contact published, and no
  bug-bounty programme found on HackerOne, Bugcrowd or Intigriti. The automated probe's initial hit on
  https://tradeshift.com/security/ was a keyword match on the "Vulnerability Management and Incident Response"
  section of the security whitepaper, not a disclosure channel; it is recorded here honestly rather than counted as a
  programme.
policy: []
contact: []
bug_bounty: null
security_policy_page: https://tradeshift.com/security/
published_practice:
  - Regular vulnerability scanning and penetration testing.
  - A defined incident response plan covering identify, contain, eradicate and recover.
  - Regular mock incident-response tests.
  - Source code reviewed and scanned for security issues before and after release.
  - Periodic scanning for out-of-date software, libraries and misconfiguration.
probes:
  - url: https://tradeshift.com/.well-known/security.txt
    http_status: 404
  - url: https://api.tradeshift.com/.well-known/security.txt
    http_status: 405
  - url: https://developers.tradeshift.com/.well-known/security.txt
    http_status: 200
    rejected: true
    reason: SPA catch-all HTML shell, not a security.txt
  - url: https://mcp.tradeshift.com/.well-known/security.txt
    http_status: 401
  - url: https://tradeshift.com/responsible-disclosure/
    http_status: 404
  - url: https://tradeshift.com/vulnerability-disclosure/
    http_status: 404
  - url: https://hackerone.com/tradeshift
    http_status: 404
evidence:
  - source: https://tradeshift.com/security/
    kind: security policy page
    keywords: [vulnerability management, incident response, penetration tests]
gap:
  - No RFC 9116 security.txt on any Tradeshift host.
  - No published disclosure contact or coordinated-disclosure policy.
  - No public bug bounty programme.
x-evidence:
  fetched: '2026-08-02'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tradeshift-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.