upGrad · Vulnerability Disclosure

Upgrad Vulnerability Disclosure

Vulnerability disclosure

upGrad runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

EducationEdTechOnline LearningHigher EducationCertificationLearning AnalyticsPartner ManagementIndia
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-02'
method: probed
probe: true
published: false
policy: []
contact: []
summary: upGrad carries a HackerOne domain-verification TXT record on upgrad.com, which is placed to prove asset
  ownership for a HackerOne program - but no PUBLIC program, policy or disclosure page could be found, so the program
  appears to be private/invite-only. No security.txt is served. No Security or VulnerabilityDisclosure pointer is
  emitted, because neither a policy nor a contact is publicly readable.
evidence:
- source: dns:TXT upgrad.com
  kind: hackerone-domain-verification
  value: h1-domain-verification=sWWQhbwPcfAgdLtYwVPsjEF9XsS9rurxPF6KYkRWc1f8urV5
  note: Real HackerOne asset-verification record - evidence a program relationship exists
- source: https://hackerone.com/graphql
  kind: program-lookup
  http_status: 200
  value: team(handle:"upgrad") -> NOT_FOUND "Team does not exist"
  note: No public HackerOne program page exists for this handle
- source: https://hackerone.com/upgrad
  kind: page-probe
  http_status: 200
  note: 200 is the HackerOne SPA shell; the control https://hackerone.com/not-a-real-program-zzz9981 returned 404,
    but /upgrad/policy_scopes returned 404 and the GraphQL team lookup is NOT_FOUND - not a published program
- source: https://www.upgrad.com/.well-known/security.txt
  kind: security.txt
  http_status: 403
  note: 403 AccessDenied from an S3 origin - no RFC 9116 document served
remedy: Publish /.well-known/security.txt (RFC 9116) with a Contact and Policy URI, and a public responsible-disclosure
  page, so a researcher who finds something can route it without an invite.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/upgrad-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.