Willow Wealth · Vulnerability Disclosure

Yieldstreet Vulnerability Disclosure

Vulnerability disclosure

Willow Wealth runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyAlternative InvestmentsPrivate MarketsInvestingWealth ManagementFinancial ServicesFintechReal EstatePrivate Credit
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@willowwealth.com

Source

Vulnerability Disclosure

yieldstreet-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-05'
method: searched
probe: true
source: https://www.willowwealth.com/.well-known/security.txt
policy:
- https://www.willowwealth.com/vulnerability-disclosure-policy
contact:
- mailto:security@willowwealth.com
preferred_languages:
- en
canonical: https://www.willowwealth.com/.well-known/security.txt
expires: '2028-06-01T03:59:00.000Z'
hiring: https://www.willowwealth.com/careers
bug_bounty: null
bug_bounty_note: >-
  No HackerOne, Bugcrowd or Intigriti program was found for willowwealth.com or the
  legacy yieldstreet.com. The RFC 9116 security.txt names a first-party disclosure
  policy page and a security@ mailbox only.
evidence:
- source: well-known/yieldstreet-security.txt
  kind: security.txt
  url: https://www.willowwealth.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain
- source: https://www.willowwealth.com/vulnerability-disclosure-policy
  kind: disclosure-policy-page
  http_status: 403
  note: >-
    Asserted by the provider's own security.txt Policy field. The page body could not be
    read directly - a Cloudflare bot-management interstitial answered 403 for every HTML
    path on this host.