generated: '2026-08-27' method: searched source: https://www.chainalysis.com/vulnerability-disclosure-policy/ description: >- Chainalysis publishes a named Vulnerability Disclosure Policy as an HTML page. It is a responsible-disclosure programme, not a paid bug bounty, and it enumerates the in-scope systems by hostname - which is the most useful part of it for API consumers, because it is the only place Chainalysis publicly names its production API hosts. program: present: true type: responsible-disclosure name: Chainalysis Vulnerability Disclosure Policy url: https://www.chainalysis.com/vulnerability-disclosure-policy/ http_status: 200 last_updated: '2024-05-15' bug_bounty: false paid_rewards: false platform: none platform_note: >- No HackerOne, Bugcrowd, Intigriti or YesWeHack programme was found. Reports are taken by email; the address is obfuscated on the published page. safe_harbor: partial public_recognition: true scope: in_scope: - host: chainalysis.com resolves: true - host: reactor.chainalysis.com resolves: true probed_status: 200 - host: kyt.chainalysis.com resolves: true probed_status: 200 - host: kryptos.chainalysis.com resolves: true probed_status: 301 probe_note: 301 to https://kyt.chainalysis.com/entities/services - host: api.sanctions.chainalysis.com resolves: false probed_status: null probe_note: >- STALE ENTRY. This hostname does not resolve - `curl` fails with "Could not resolve host" and dig returns no record. Chainalysis lists a non-existent host as in-scope for security research, which is a small but real hygiene defect in the policy. out_of_scope: - Spam - Social engineering - DDoS attacks excluded_from_response: - Bulk submissions - Issues already known to Chainalysis - Issues of negligible impact requirements: - Provide a detailed description, URL, and screenshots or sample code. - Avoid accessing or destroying user data. - Stop testing once a vulnerability is established. - Keep details confidential until Chainalysis confirms the issue is resolved. commitments: - Promptly investigate reports. - Fix confirmed vulnerabilities. - Publicly recognise researchers. security_txt: present: false note: >- No /.well-known/security.txt on any Chainalysis host (404 on www, 410 on api, 403 on public and docs). Publishing an RFC 9116 security.txt pointing at this policy page would make the programme machine-discoverable at effectively zero cost - it is the single cheapest security-surface improvement available here. evidence: - url: https://www.chainalysis.com/vulnerability-disclosure-policy/ status: 200 - url: https://www.chainalysis.com/.well-known/security.txt status: 404 - url: https://api.sanctions.chainalysis.com/ status: null note: DNS resolution failure