Upstream Security · Vulnerability Disclosure

Upstream Security Vulnerability Disclosure

Vulnerability disclosure

Upstream Security publishes a vulnerability disclosure policy for reporting security issues.

CompanySecurityCybersecurityAutomotiveConnected VehiclesMobilityIoTThreat Intelligence
Program:

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

upstream-security-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-21'
method: searched
probe: true
policy:
  - https://upstream.auto/upstreams-vulnerability-disclosure-policy/
report:
  - https://docs.google.com/forms/d/e/1FAIpQLSf0-pwZCMpmQLgMR4J6KnfWS1brrxoi3VLV332hvbllG-NQ6Q/viewform
contact: []
security_txt: false
program:
  name: Upstream's Vulnerability Disclosure Policy (VDP)
  safe_harbor: true
  qualifying:
    - 'Injection flaws (SQL injection, command injection)'
    - Authentication and session issues (broken authentication, session hijacking, bypasses)
    - Cross-site scripting (stored or reflected XSS)
    - Access control (IDOR, privilege escalation)
    - 'Sensitive data exposure (unprotected API keys, PII leaks, exposed credentials)'
    - Server-side request forgery (SSRF)
    - Prompt injections on applications and agents built by Upstream Security
  out_of_scope:
    - Third-party services not owned by Upstream Security
    - Social engineering (phishing, vishing, smishing)
    - Physical security of offices or data centers
    - Denial of service (DoS/DDoS) testing
    - Spamming and automated form submissions
  non_qualifying:
    - Missing security headers (CSP, HSTS) without a direct exploit
    - Rate limiting issues on non-critical forms
    - Username/email enumeration on login pages
    - Self-XSS and vulnerabilities requiring unlikely user interaction
evidence:
  - source: https://upstream.auto/upstreams-vulnerability-disclosure-policy/
    kind: disclosure-page
    keywords: [vulnerability disclosure policy, safe harbor, report security issue]
notes: >-
  No /.well-known/security.txt (probed 404 on upstream.auto, 2026-07-21) and no
  public bug bounty platform program found; disclosure runs through the VDP page
  and a Google Form report channel. The VDP explicitly covers prompt injection
  on Upstream-built applications and agents.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/upstream-security-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.