Upstart Vulnerability Disclosure
Upstart publishes an RFC 9116 security.txt at https://www.upstart.com/.well-known/security.txt (served on both www.upstart.com and api.upstart.com; Canonical points at www). It directs reports to a vulnerability-reporting page under the lender regulatory-compliance section and documents a private bug bounty program reachable by emailing security@upstart.com for an invite. Note: the security.txt Expires field (2025-09-01) is in the past - the file is stale per RFC 9116 but still served.
Upstart publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.