specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: Cloudability providerId: cloudability generated: '2026-09-05' modified: '2026-09-05' method: searched source: >- https://www.apptio.com/company/trust/ (Apptio Trusted Platform page) and the live security.txt at https://www.ibm.com/.well-known/security.txt, both fetched 2026-09-05. description: >- Cloudability publishes no vulnerability-disclosure document on any cloudability.com or apptio.com host. Disclosure runs through two published routes: a named Apptio security mailbox on the Apptio trust page, and IBM's corporate PSIRT programme (Cloudability is an IBM Apptio product), which operates a public HackerOne bug-bounty team and serves a conformant security.txt. program: published: true security_txt: served: true url: https://www.ibm.com/.well-known/security.txt host: www.ibm.com http_status: 200 content_type: text/plain file: ../well-known/cloudability-security.txt expires: '2026-10-05T00:00:00+00:00' note: >- IBM corporate PSIRT security.txt. Not served on a cloudability.com or apptio.com host — those return 404 (www.apptio.com), redirects (cloudability.com, apptio.com), an SPA shell (app.cloudability.com) or a blanket 401 (api.cloudability.com). contacts: - type: email value: infosec@apptio.com source: https://www.apptio.com/company/trust/ scope: Apptio / Cloudability product security - type: email value: psirt@us.ibm.com source: https://www.ibm.com/.well-known/security.txt scope: IBM corporate PSIRT - type: url value: https://www.ibm.com/trust/security-psirt source: https://www.ibm.com/.well-known/security.txt scope: IBM PSIRT policy and reporting page bug_bounty: platform: HackerOne url: https://hackerone.com/ibm?type=team http_status: 200 verified: '2026-09-05' note: >- Published in IBM's security.txt Contact field. Covers IBM products; scope for Cloudability specifically is decided inside the HackerOne programme and is not stated in the security.txt. encryption_key: https://www.ibm.com/downloads/documents/us-en/15db45ee46d2037d acknowledgments: https://www.ibm.com/blogs/psirt/ibm-acknowledgement/ gaps: - >- No security.txt on any host a Cloudability API consumer would try first — api.cloudability.com, app.cloudability.com, www.cloudability.com or www.apptio.com. A researcher has to already know the product belongs to IBM to find the disclosure route. - >- The IBM security.txt Expires field is 2026-10-05, one month out from this probe. It is current, but it is the shortest-lived document in this record.