Zero Hash · Vulnerability Disclosure

Zero Hash Vulnerability Disclosure

Vulnerability disclosure

Zero Hash runs a coordinated vulnerability disclosure program on Bugcrowd. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyCrypto InfrastructureDigital AssetsStablecoinsPaymentsPayoutsTokenizationCustodyStakingSettlementEmbedded FinanceOn-Off RampLiquidityFIX ProtocolWebhookWebSocketsKYCComplianceRemittancesAgentic Finance
Program: Bugcrowd security.txt present

Disclosure Policy

Security Contact

Contact
https://zerohash.com/vdp
Contact
mailto:zerohash-vdp-ess@submit.bugcrowd.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-05'
method: searched
probe: true
source: https://zerohash.com/.well-known/security.txt
security_txt:
  url: https://zerohash.com/.well-known/security.txt
  http_status: 200
  canonical: https://zerohash.com/.well-known/security.txt
  expires: '2027-03-20T14:00:00.000Z'
  preferred_languages: en
  file: ../well-known/zero-hash-security.txt
policy_url: https://zerohash.com/vdp
contact:
- https://zerohash.com/vdp
- mailto:zerohash-vdp-ess@submit.bugcrowd.com
bug_bounty:
  platform: Bugcrowd
  program_type: vulnerability disclosure program (VDP)
  recognition: >-
    "We hope to provide recognition for findings through Bugcrowd." The security page describes the program as
    designed to recognize security researchers for finding and responsibly reporting vulnerabilities in zerohash
    products and services.
  submission_alias: zerohash-vdp-ess@submit.bugcrowd.com
hiring: https://www.linkedin.com/company/zerohash/jobs/
gaps:
- >-
  security.txt declares no Policy, Encryption or Acknowledgments field — only Contact, Expires,
  Preferred-Languages, Canonical and Hiring.
- >-
  No public safe-harbor or in-scope/out-of-scope statement was found beyond the program description.
evidence:
- source: https://zerohash.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain; charset=utf-8
- source: https://zerohash.com/vdp
  http_status: 200
- source: https://zerohash.com/security
  http_status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/zero-hash-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.