Yuanfudao · Vulnerability Disclosure

Yuanfudao Vulnerability Disclosure

Vulnerability disclosure

Yuanfudao publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyEducationEdTechOnline LearningTutoringArtificial IntelligenceMobile ApplicationsChina
Program:

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
auth_methodsQQ loginWeChat login
Contact
auth_required_to_submittrue
Contact
emailsecurity@kanyun.com
Contact
submission_urlhttps://security.kanyun.com/user.php?m=user&c=post&a=add

Source

Vulnerability Disclosure

yuanfudao-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-04'
method: searched
source: https://security.kanyun.com/
name: Kanyun Security Response Center (YSRC / 看云安全应急响应中心)
program:
  present: true
  operator: Kanyun Holdings Group (看云控股集团) — Yuanfudao's parent group
  url: https://security.kanyun.com/
  alternate_url: https://security.yuanfudao.com/
  platform: Tencent xSRC (self-hosted instance, "Powered by Tencent xSRC")
  platform_url: https://security.tencent.com/index.php/xsrc
  type: self-hosted vulnerability disclosure program with rewards
  bug_bounty: true
  reward_model: >-
    Points ("安全币" / security coins) redeemable for cash and merchandise, plus quarterly awards.
    The public gift catalog lists a 100 CNY cash redemption at 100 coins and branded merchandise
    at 39 coins.
contact:
  email: security@kanyun.com
  submission_url: https://security.kanyun.com/user.php?m=user&c=post&a=add
  auth_required_to_submit: true
  auth_methods:
  - QQ login
  - WeChat login
policy:
  url: https://security.kanyun.com/index.php?a=view&c=page&id=14
  title: 看云安全应急中心(YSRC)标准漏洞处理及评分标准 (YSRC standard vulnerability handling and scoring standard)
  version_observed: V1.3 (page id=14, published 2024-04-02); V1.7 is the current version linked from the homepage
  testing_rules_url: https://security.yuanfudao.com/index.php?m=&c=page&a=view&id=2
  testing_rules_title: SRC 行业安全测试规范 (industry security testing code of conduct)
  sla:
    triage: within 1 business day (status moves to "审核中" / under review)
    assessment: within 3 business days (severity rating and coin award, or rejection)
scope:
  statement: >-
    Products and business systems operated by Kanyun Holdings Group, including but not limited to
    the wildcard domains listed below, plus the group's servers and its published PC, mobile and
    mini-program clients. The policy text explicitly excludes classup-related vulnerabilities.
  in_scope_domains:
  - '*.zhenguanyu.com'
  - '*.yuanfudao.com'
  - '*.yuantiku.com'
  - '*.yuansouti.com'
  - '*.xiaoyuankousuan.com'
  - '*.banmaaike.com'
  - '*.ybccode.com'
  - '*.skypeople.com'
  - '*.gridcoffee.com'
  - '*.moliyuezi.com'
  - '*.motiff.com'
  excluded:
  - classup (vulnerabilities no longer accepted)
security_txt:
  served: false
  note: >-
    No /.well-known/security.txt is served on yuanfudao.com, www.yuanfudao.com or
    security.kanyun.com — all probed 2026-09-04 and returned 404. The disclosure program is
    discoverable only through the human-facing YSRC portal, not through RFC 9116.
x-evidence:
  fetched: '2026-09-04'
  probes:
  - url: https://security.kanyun.com/
    http_status: 200
    note: YSRC portal homepage, live
  - url: https://security.yuanfudao.com/
    http_status: 301
    note: redirects to https://security.kanyun.com/
  - url: https://security.kanyun.com/index.php?a=view&c=page&id=14
    http_status: 200
    note: scoring standard V1.3, carries the in-scope domain list
  - url: https://www.yuanfudao.com/.well-known/security.txt
    http_status: 404
notes:
- >-
  The program covers the whole Kanyun group, not Yuanfudao alone. Domains named in its scope that
  belong to sibling brands (motiff.com — Motiff AI design tool; gridcoffee.com — Grid Coffee;
  skypeople.com) are recorded here as published scope, not as Yuanfudao properties.
- >-
  This is a security-reporting surface, not an API. It is the only machine-addressable developer-
  facing program Yuanfudao/Kanyun publishes.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/yuanfudao-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.