Wand · Vulnerability Disclosure

Wand Ai Vulnerability Disclosure

Vulnerability disclosure

Wand serves a valid but minimal RFC 9116 security.txt across its subdomains. It carries only the two mandatory-plus-contact fields — Contact and Expires — and nothing else: no Policy URL, no Encryption key, no Acknowledgments, no Preferred-Languages, no Canonical. There is no disclosure policy page and no bug-bounty program.

Wand runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyArtificial IntelligenceAI AgentsAgentic AIEnterprise SoftwareWorkforce AutomationOrchestrationProcess AutomationCollaborationGovernance
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:giorgio.diguardia@wand.ai

Source

Vulnerability Disclosure

wand-ai-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-04'
method: searched
probe: true
source: >-
  https://auth.wand.ai/.well-known/security.txt (HTTP 200, saved verbatim to
  well-known/wand-ai-security.txt), plus direct probes of the common disclosure page paths on
  wand.ai and a search for a Wand bug-bounty program.
name: Wand vulnerability disclosure
description: >-
  Wand serves a valid but minimal RFC 9116 security.txt across its subdomains. It carries only the
  two mandatory-plus-contact fields — Contact and Expires — and nothing else: no Policy URL, no
  Encryption key, no Acknowledgments, no Preferred-Languages, no Canonical. There is no disclosure
  policy page and no bug-bounty program.
security_txt:
  present: true
  file: well-known/wand-ai-security.txt
  rfc: RFC 9116
  served_from:
  - https://auth.wand.ai/.well-known/security.txt
  - https://api.wand.ai/.well-known/security.txt
  - https://status.wand.ai/.well-known/security.txt
  - https://staging.wand.ai/.well-known/security.txt
  - https://grafana.wand.ai/.well-known/security.txt
  not_served_from:
  - url: https://wand.ai/.well-known/security.txt
    status: 404
    note: >-
      The apex is the HubSpot-hosted marketing site and is not covered by the edge rule that serves
      the file on every other subdomain. This is the host a researcher would try first.
  fields_present: [Contact, Expires]
  fields_absent: [Policy, Encryption, Acknowledgments, Preferred-Languages, Canonical, Hiring, CSAF]
  expires: '2028-12-30T10:00:00Z'
  expires_valid: true
  signed: false
contact:
- mailto:giorgio.diguardia@wand.ai
policy_url: null
bug_bounty:
  present: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  result: no Wand AI program found
disclosure_pages_probed:
- {url: 'https://wand.ai/security', status: 404}
- {url: 'https://wand.ai/trust', status: 404}
- {url: 'https://wand.ai/compliance', status: 404}
- {url: 'https://wand.ai/.well-known/security.txt', status: 404}
- {host: 'trust.wand.ai', dns: 'NXDOMAIN'}
- {host: 'security.wand.ai', dns: 'NXDOMAIN'}
evidence:
- source: https://auth.wand.ai/.well-known/security.txt
  http_status: 200
  content_type: text/plain; charset=utf-8
  bytes: 72
  fetched: '2026-09-04'
gaps:
- The apex domain wand.ai 404s its own security.txt.
- No Policy field, so a reporter has no published terms, scope, or safe-harbour statement.
- Contact is a single named individual's mailbox rather than a role address such as security@wand.ai.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/wand-ai-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.