Upstart · Vulnerability Disclosure

Upstart Vulnerability Disclosure

Vulnerability disclosure

Upstart publishes an RFC 9116 security.txt at https://www.upstart.com/.well-known/security.txt (served on both www.upstart.com and api.upstart.com; Canonical points at www). It directs reports to a vulnerability-reporting page under the lender regulatory-compliance section and documents a private bug bounty program reachable by emailing security@upstart.com for an invite. Note: the security.txt Expires field (2025-09-01) is in the past - the file is stale per RFC 9116 but still served.

Upstart publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyFintechLendingCreditArtificial IntelligencePersonal LoansBankingMarketplace
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://www.upstart.com/lenders/regulatory-compliance/vulnerability-reporting/
Contact
security@upstart.com

Source

Vulnerability Disclosure

upstart-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-21'
method: searched
probe: true
source: well-known/upstart-security.txt
description: >-
  Upstart publishes an RFC 9116 security.txt at
  https://www.upstart.com/.well-known/security.txt (served on both
  www.upstart.com and api.upstart.com; Canonical points at www). It directs
  reports to a vulnerability-reporting page under the lender
  regulatory-compliance section and documents a private bug bounty program
  reachable by emailing security@upstart.com for an invite. Note: the
  security.txt Expires field (2025-09-01) is in the past - the file is stale
  per RFC 9116 but still served.
policy:
  - https://www.upstart.com/lenders/regulatory-compliance/vulnerability-reporting/
contact:
  - https://www.upstart.com/lenders/regulatory-compliance/vulnerability-reporting/
  - security@upstart.com
bug_bounty:
  program: private
  platform: null
  invite: 'email security@upstart.com with subject "Bug Bounty Invite: <username>"'
security_txt:
  canonical: https://www.upstart.com/.well-known/security.txt
  expires: '2025-09-01T12:00:00Z'
  stale: true
  preferred_languages: en
evidence:
  - source: well-known/upstart-security.txt
    kind: security.txt (RFC 9116, fetched live 2026-07-21)
  - source: https://www.upstart.com/lenders/regulatory-compliance/vulnerability-reporting/
    kind: vulnerability reporting page (HTTP 200)