generated: '2026-07-22' method: searched probe: true policy: [https://alpaca.markets/security] contact: [bugreport@alpaca.markets] program: type: invite-based bug bounty description: >- Alpaca runs an invite-based bug bounty: researchers who suspect a security flaw submit a request to bugreport@alpaca.markets to be invited to the program, with rewards for valid issues that align with the bug bounty policy. No public HackerOne/Bugcrowd program. evidence: - source: https://alpaca.markets/security kind: security-page keywords: [vulnerability disclosure, bug bounty program, security researchers] - source: https://alpaca.markets/security (mailto, Cloudflare-deobfuscated) kind: contact value: bugreport@alpaca.markets notes: >- No RFC 9116 security.txt is published on any Alpaca host (alpaca.markets serves a soft-404 HTML page at /.well-known/security.txt).