generated: '2026-08-11' method: searched probe: true source: https://runalphaloops.com/security description: >- AlphaLoops publishes a "Report a Vulnerability" section on its public security page inviting responsible disclosure by email, with a stated 24-hour response commitment. There is no security.txt served on any host, no bug-bounty program (HackerOne / Bugcrowd / Intigriti), and no published safe-harbor or scope statement. program: exists: true type: email-disclosure formal_policy_published: false bug_bounty: false bounty_platform: null safe_harbor_published: false scope_published: false disclosure_page: https://runalphaloops.com/security contact_email: security@runalphaloop.com response_commitment: 24 hours verbatim: >- "Found a security issue? We appreciate responsible disclosure. Please email us with details and we'll respond within 24 hours. security@runalphaloop.com" # DEFECT WORTH REPORTING TO THE PROVIDER — the published security contact uses the domain # "runalphaloop.com" (SINGULAR "loop"), while the company, its site, its API and its MCP server # all live on "runalphaloops.com" (PLURAL). The same singular-domain address appears as the # general contact (hello@runalphaloop.com) in the site footer and in the OpenAPI info.contact # block. If runalphaloop.com is not a domain AlphaLoops controls and routes, the advertised # vulnerability-reporting channel does not reach them. anomalies: - kind: contact-domain-mismatch severity: high detail: >- Security contact security@runalphaloop.com and general contact hello@runalphaloop.com use runalphaloop.com (singular), but every operational host is runalphaloops.com (plural). observed_at: - https://runalphaloops.com/security - https://runalphaloops.com/pricing - https://runalphaloops.com/openapi.json remediation: >- Confirm runalphaloop.com is owned and receiving mail, or correct the published addresses to @runalphaloops.com across the security page, site footer and OpenAPI info.contact. security_txt: served: false probed: - url: https://runalphaloops.com/.well-known/security.txt http_status: 200 result: miss note: SPA catch-all returns the marketing HTML shell for every path; not a security.txt. - url: https://api.runalphaloops.com/.well-known/security.txt http_status: 404 result: miss - url: https://mcp-freight.runalphaloops.com/.well-known/security.txt http_status: 404 result: miss evidence: - url: https://runalphaloops.com/security http_status: 200 kind: disclosure page keywords: - Report a Vulnerability - responsible disclosure - security@