TREBEL Music · Vulnerability Disclosure

Trebel Music Vulnerability Disclosure

Vulnerability disclosure

TREBEL Music runs a first-party vulnerability disclosure and bug bounty program published at home.trebel.io/bug-program. It is self-hosted (submission web form) rather than run on HackerOne, Bugcrowd or Intigriti, and no RFC 9116 security.txt advertises it — the page was found by crawling the site's own sitemap.xml.

TREBEL Music runs a coordinated vulnerability disclosure program on Hackerone.

CompanyMusicMusic StreamingMediaEntertainmentMobile AppsAdvertisingConsumer
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

trebel-music-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-30'
method: searched
source: https://home.trebel.io/bug-program
name: TREBEL Music Bug Bounty Program
description: >-
  TREBEL Music runs a first-party vulnerability disclosure and bug bounty program published
  at home.trebel.io/bug-program. It is self-hosted (submission web form) rather than run on
  HackerOne, Bugcrowd or Intigriti, and no RFC 9116 security.txt advertises it — the page was
  found by crawling the site's own sitemap.xml.
program:
  present: true
  type: bug-bounty
  self_hosted: true
  platform: null
  policy_url: https://home.trebel.io/bug-program
  submission: web-form
  contact_email: null
  security_txt: false
  rewards:
    offered: true
    basis: >-
      "Rewards are provided at TREBEL's discretion based on the severity of the bug and the
      quality of the report."
    published_amounts: false
  eligibility:
  - Vulnerability must be verifiable and reproducible.
  - Vulnerability must not have been previously reported.
  - Researcher must comply with the published program guidelines.
  out_of_scope:
  - Privacy violations against TREBEL users.
  - Destruction or deletion of data / damage to resources.
  - Any activity causing lasting harm to TREBEL services.
  - Targeting TREBEL staff, investors, or physical property.
  safe_harbor:
    stated: true
    note: >-
      TREBEL states it will not pursue legal action against researchers who comply with the
      program, and will defend a compliant researcher if a third party initiates legal action
      over in-scope activity.
x-evidence:
  fetched: '2026-08-30'
  probes:
  - url: https://home.trebel.io/bug-program
    status: 200
  - url: https://home.trebel.io/.well-known/security.txt
    status: 404
  - url: https://api.trebel.io/.well-known/security.txt
    status: 404
  - url: https://home.trebel.io/security
    status: 404
  - url: https://home.trebel.io/responsible-disclosure
    status: 404
gaps:
- >-
  No /.well-known/security.txt on any TREBEL host. Publishing one (RFC 9116) with
  Policy: https://home.trebel.io/bug-program would make the program machine-discoverable.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/trebel-music-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.