Vanilla Steel · Vulnerability Disclosure

Vanilla Steel Vulnerability Disclosure

Vulnerability disclosure

Vanilla Steel publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanySteelMetalsMarketplaceTradingB2BProcurementRFQLogistics
Program:

Disclosure Policy

Security Contact

Contact
security@vanillasteel.com

Source

Vulnerability Disclosure

vanilla-steel-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-21'
method: searched
probe: true
source: https://vanillasteel.com/software/terms
policy: []
contact:
- security@vanillasteel.com
evidence:
- source: https://vanillasteel.com/software/terms
  kind: terms-of-service
  section: '9. Security'
  quote: You must notify Vanilla Steel promptly at security@vanillasteel.com if you
    become aware of unauthorised access, a security incident, or any other event
    involving Customer Data or the Services.
notes: No /.well-known/security.txt (404 on vanillasteel.com; SPA fallback on app.vanillasteel.com),
  no bug-bounty program, and no dedicated responsible-disclosure page were found
  by the security-programs probe. The published security contact is the security-incident
  channel documented in Section 9 of the Vanilla Steel Terms of Service (effective
  22 May 2026), not a formal vulnerability disclosure policy.