Tray.ai · Vulnerability Disclosure

Tray Ai Vulnerability Disclosure

Vulnerability disclosure

Tray.ai runs a bug bounty program with a private HackerOne intake. The intake URL is published as the "Report a Vulnerability" quick link on Tray's Conveyor-hosted trust center, and the program is stated in prose on tray.ai/trust: "Tray's security is tested by independent experts. We complete SOC 1 and SOC 2 Type 2 audits, conduct annual penetration tests, and run a bug bounty program with the security community."

Tray.ai runs a coordinated vulnerability disclosure program on Hackerone.

AutomationIntegrationiPaaSAI AgentsMCPOrchestrationWorkflow AutomationConnectorsAgent GatewayEmbedded IntegrationEnterprise AutomationModel Context Protocol
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-02'
method: searched
source: https://trust.tray.ai/
provider: Tray.ai
providerId: tray-ai
has_program: true
program_type: bug-bounty
description: >-
  Tray.ai runs a bug bounty program with a private HackerOne intake. The intake URL is published
  as the "Report a Vulnerability" quick link on Tray's Conveyor-hosted trust center, and the
  program is stated in prose on tray.ai/trust: "Tray's security is tested by independent experts.
  We complete SOC 1 and SOC 2 Type 2 audits, conduct annual penetration tests, and run a bug
  bounty program with the security community."
report_url: https://hackerone.com/a15ee773-fdbf-4a7b-9942-43bec427b5ea/embedded_submissions/new
platform: HackerOne
platform_note: >-
  An embedded HackerOne submission form keyed on a program UUID rather than a public handle —
  https://hackerone.com/tray_io returns 404, so the program is not publicly listed. The form is
  the only intake Tray publishes.
security_txt:
  served: false
  probed:
    - url: https://tray.ai/.well-known/security.txt
      status: 404
    - url: https://tray.io/.well-known/security.txt
      status: 404
    - url: https://api.tray.io/.well-known/security.txt
      status: 404
    - url: https://tray.ai/security.txt
      status: 404
  gap: >-
    No RFC 9116 security.txt on any Tray host. Publishing one at
    https://tray.ai/.well-known/security.txt with Contact and Policy pointing at the HackerOne
    form would make this program machine-discoverable; today a researcher has to find the trust
    center first.
independent_testing:
  penetration_tests: annual
  audits: [SOC 1 Type 2, SOC 2 Type 2]
  auditor: Schellman & Company, LLC
  source: https://tray.ai/trust
security_advisories:
  published_on: https://trust.tray.ai/
  examples:
    - date: '2024-04-03'
      title: XZ Utils (liblzma) SSH Vulnerability - No Impact (CVE-2024-3094)
    - date: '2023-06-10'
      title: MOVEit Vulnerability - No Impact
contact_route:
  security_questionnaire: >-
    tray.ai/trust states "Need a security questionnaire, pen test report, or signed DPA? The trust
    team responds in one business day." — routed through a web form, not a published address.
evidence:
  - url: https://trust.tray.ai/
    status: 200
    finding: >-
      quickLinks entry {"displayText":"Report a Vulnerability","urlLink":"https://hackerone.com/a15ee773-fdbf-4a7b-9942-43bec427b5ea/embedded_submissions/new"}
      and vendor record reportVulnerabilityUrl with the same value.
  - url: https://tray.ai/trust
    status: 200
    finding: '"...run a bug bounty program with the security community."'
  - url: https://hackerone.com/tray_io
    status: 404
    finding: No public HackerOne program handle.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tray-ai-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.