Start here: finding a security contact with lookup.disclose.io

Most posts in Hacker Connect are some version of “I found something at company X and I can’t find anyone to report it to.” That is exactly the problem lookup.disclose.io was built to solve, so before you post, it is worth 30 seconds there first.

What it does: you give it a domain, IP, URL, email, package name, repo, container image, mobile app, or hardware ID, and it resolves that asset to whoever you should actually contact: a security.txt, a VDP, a bug bounty program, a PSIRT, or a CERT. It chains strategies, so even when the obvious /.well-known/security.txt is missing it keeps going.

Three ways to use it:

  • Web: https://lookup.disclose.io
  • API with an OpenAPI spec (free key tier) for scripting bulk lookups
  • A hosted MCP server, if you want it inside an AI assistant

Still stuck? Then post here. If lookup comes up empty or points you at the wrong contact, that is genuinely useful to us. Reply in this category with the asset and what you were trying to reach, and (a) someone here will often know the human, and (b) it tells us where lookup’s attribution needs work so we can fix it. The threads where people tell us “lookup missed this one” are some of the most valuable on the whole forum.

So: try lookup first, and use Hacker Connect for the hard cases it cannot crack yet.