generated: '2026-08-22' method: probed source: >- Live probes of hiddenroad.com/.well-known/security.txt, hiddenroad.com's former responsible-disclosure page, and ripple.com/legal/bug-bounty/ published: false summary: >- Hidden Road has NO reachable vulnerability disclosure surface of its own. It formerly published a "Responsible Disclosure of Information" page at hiddenroad.com/disclosures/responsible-disclosure-of-information/ (present in the Wayback index); every path on hiddenroad.com now 301s to a single Ripple marketing page, so that policy is gone. No security.txt is served on any Hidden Road host. Ripple runs a bug bounty on Bugcrowd, but the published scope names only Ripple Payments, the XRP Ledger, RLUSD and the XRPL EVM Sidechain — Hidden Road, Ripple Prime and hiddenroad.com are NOT in scope. A researcher who finds a flaw in api.hiddenroad.com today has no published channel. security_txt: served: false probes: - url: https://hiddenroad.com/.well-known/security.txt status: 301 redirects_to: https://ripple.com/products/prime-brokerage/ note: Soft-404 — the redirect target is a marketing page, not a policy. - url: https://auth.hiddenroad.com/.well-known/security.txt status: 404 - url: https://api.hiddenroad.com/.well-known/security.txt status: 403 note: API Gateway "Missing Authentication Token" — path not routed. - url: https://ripple.com/.well-known/security.txt status: 404 disclosure_pages: - url: https://hiddenroad.com/disclosures/responsible-disclosure-of-information/ status: 301 live: false note: >- Existed on the pre-acquisition WordPress site (Wayback CDX). Now blanket-redirected to https://ripple.com/products/prime-brokerage/ along with every other hiddenroad.com path, including the firm's regulatory disclosures. - url: https://ripple.com/legal/bug-bounty/ status: 200 live: true platform: Bugcrowd (private, invitation-only) contact: bugs@ripple.com covers_hidden_road: false note: >- Scope as published lists Ripple Payment Products, XRP Ledger (rippled, Clio, xrpl.js, xrpl-py, xrpl4j), RLUSD contracts and the XRPL EVM Sidechain. Prime brokerage is absent. remediation: >- Serve an RFC 9116 security.txt on hiddenroad.com and api.hiddenroad.com, or add Ripple Prime and *.hiddenroad.com to the published Bugcrowd scope. Restoring the responsible-disclosure page at a stable URL would be the smallest fix.