TXOne Networks · Vulnerability Disclosure

Txone Networks Vulnerability Disclosure

Vulnerability disclosure

TXOne Networks runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySecurityCybersecurityOperational TechnologyIndustrial Control SystemsCritical InfrastructureEndpoint ProtectionNetwork SecurityVulnerability ManagementManufacturing
Program: Hackerone

Disclosure Policy

Security Contact

Contact
anonymous_reports_acceptedtrue
Contact
emailsecurity@txone.com
Contact
encryption{"fingerprint" => "FECB D146 2C36 3B04 6B2D F4E5 7314 6C66 B4E5 26C6", "pgp" => true}

Source

Vulnerability Disclosure

txone-networks-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-01'
method: searched
source: https://www.txone.com/legal/disclosure-policy/
docs:
- https://www.txone.com/legal/disclosure-policy/
- https://www.txone.com/psirt/
- https://www.txone.com/legal/security-policy/
program:
  name: TXOne Networks PSIRT (Product Security Incident Response Team)
  published: true
  policy_url: https://www.txone.com/legal/disclosure-policy/
  policy_status: 200
  program_url: https://www.txone.com/psirt/
  program_status: 200
  policy_last_updated: '2026-05-26'
  security_txt: false
  security_txt_note: >-
    No RFC 9116 /.well-known/security.txt is served on www.txone.com,
    help.txone.com or my.txone.com (all probed 2026-09-01 - see
    well-known/txone-networks-well-known.yml). The disclosure policy is published
    as an HTML page under /legal/ instead.
  bug_bounty: false
  bug_bounty_note: >-
    Stated verbatim in the policy: "TXOne Networks does not participate in a bug
    bounty awards program at this time." No HackerOne, Bugcrowd or Intigriti
    program was found.
contact:
  email: security@txone.com
  anonymous_reports_accepted: true
  encryption:
    pgp: true
    fingerprint: FECB D146 2C36 3B04 6B2D F4E5 7314 6C66 B4E5 26C6
commitments:
  acknowledgement_window: 72 hours
  coordinated_disclosure_window: 90 days
  safe_harbor: true
  safe_harbor_note: >-
    Good-faith research conducted under the policy is considered authorized;
    TXOne states it will not recommend or pursue legal action, and will make the
    authorization known if a third party initiates action.
scope:
  in_scope:
  - TXOne Networks products (Edge, Stellar, Element and Sennin/Sage product families)
  out_of_scope:
  - Network distributed denial-of-service (DDoS) testing
  - Physical testing (office access, tailgating) and social engineering (phishing, vishing)
  - Services hosted by third-party providers
advisories:
  published: true
  channels:
  - name: Security bulletins in the TXOne Help Center
    url: https://help.txone.com/
    note: >-
      Product security bulletins are published as Help Center articles, e.g.
      "Security Bulletin - Improper Access Control Vulnerability" and
      "Security Bulletin - StellarProtect Legacy Mode / StellarEnforce / Safe Lock
      Improper Validation of Integrity Check Value Vulnerability".
  - name: CVE advisories index
    url: https://www.txone.com/legal/
  - name: TXOne Threat Research
    url: https://www.txone.com/company/ot-threat-research/

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/txone-networks-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.