generated: '2026-08-02' method: searched probe: true probe_result: none probe_note: > probe-security-programs.py returned vdp=none — there is no /.well-known/security.txt on any Clear Street host, and none of the conventional disclosure paths (/security/responsible-disclosure, /responsible-disclosure, /vulnerability-disclosure, /security) exist at the apex. The security page lives at /legal/security on the corporate site, which the mechanical probe does not reach. status: contact-only status_note: > Clear Street publishes a security CONTACT and a security program page, but NOT a formal vulnerability disclosure policy: there is no stated scope, no safe-harbour language, no response-time commitment, and no bug bounty program. Recorded honestly as contact-only. policy: [] policy_url: https://www.clearstreet.io/legal/security contact: - security@clearstreet.io security_txt: published: false probed_hosts: [clearstreet.io, www.clearstreet.io, clearstreet.com, www.clearstreet.com, api.clearstreet.com, api.clearstreet.io, docs.clearstreet.com, docs.clearstreet.io, auth.clearstreet.io] http_status: 404 rfc: RFC 9116 gap: > Adding /.well-known/security.txt with Contact: mailto:security@clearstreet.io and a Policy: URL would be a one-file fix that makes the existing contact machine-discoverable. bug_bounty: published: false checked: [HackerOne, Bugcrowd, Intigriti, YesWeHack] sdk_security_policy: present: true note: > Every first-party SDK, CLI and the skills repository ships a SECURITY.md and a `security` GitHub Actions workflow, so per-repository reporting guidance does exist even though the corporate site carries no VDP. repos: [clear-street-python, clear-street-typescript, clear-street-go, clear-street-java, clear-street-cli, studio-sdk-python, studio-sdk-node, studio-sdk-java, clearstreet-skills] evidence: - {source: 'https://www.clearstreet.io/legal/security', kind: security-page, http_status: 200, keywords: ['security@clearstreet.io', 'security controls', 'trust center']} - {source: 'https://www.clearstreet.io/legal/clear-street-trust-center', kind: trust-center, http_status: 200, keywords: ['vulnerability management', 'incident response']} - {source: 'https://github.com/clear-street/clearstreet-skills/blob/main/SECURITY.md', kind: repo-security-policy} x-evidence: fetched: '2026-08-02' probes_missed: - {url: 'https://www.clearstreet.io/.well-known/security.txt', http_status: 404} - {url: 'https://www.clearstreet.com/.well-known/security.txt', http_status: 404} - {url: 'https://auth.clearstreet.io/.well-known/security.txt', http_status: 404}