Changelog
What's new in lookup — the tool that turns any internet asset into the right security-disclosure contact. Newest first.
Registry placeholders no longer become owners. Values such as “There is no organizer” are rejected as owner names, along with their unsupported country hints. Registrar names and registration dates also stay out of the ownership evidence when no registrant organization is known.
IHFood now resolves to its named owner and official policy. Reviewed, expiring policy evidence identifies IHFood A/S and adds its published vulnerability disclosure policy. Its existing security mailboxes keep their authority, and live and reviewed reporting channels stay together under one owner.
Blocked security.txt checks remain inconclusive. HTTP blocks, rate limits, and server errors no longer make security.txt look absent. Absence requires conclusive negative results from both candidate locations; a valid published contact on either location still takes precedence.
More coordinator-only results now reach a defensible owner route. Reviewed first-party policies cover MassMutual, RIT, and Nmap; exact current scope connects Outlook and NetSuite to their published reporting process; and a website-linked GitHub organization can supply its default SECURITY.md only when the organization account, profile website, and GitHub verified-domain badge all agree. Ambiguous accounts and off-owner contacts still abstain.
Corporate context no longer implies disclosure scope. Outlook is shown under Microsoft and Talabat under Delivery Hero, but a parent route becomes first-party only when the parent's current policy explicitly includes the queried asset. A brand relationship by itself remains a clearly labelled related-party option.
Product ideas now have a dedicated home. A new product feedback form accepts general feedback, feature requests, and a reply address without mixing personal contact details into lookup-result quality telemetry.
Official policies behind bot defenses and deep sitemaps are no longer dead ends. lookup now prioritizes legal, global, and help sitemap branches and can follow an owner-endorsed security portal on the same organization domain. When an official policy blocks automated access, short-lived, human-reviewed evidence can preserve its exact reporting route without guessing ownership. This brings Bunnings, TCL, and Motorola Solutions to their published channels. A current security.txt or DNS Security TXT declaration remains authoritative and always ranks first.
“Complete” now means a route to the actual owner. Publisher, maintainer, build host, identifier assignee, parent, and disclosure-platform relationships remain useful context, but cannot silently become ownership or make a lookup complete. Exact owner evidence and scope-matched reporting channels decide the headline.
Ownership evidence is more skeptical. TLS attribution reads only the verified leaf certificate, privacy proxies and commercial registrants on government namespaces no longer become owners, and certificate-incident or advertising metadata stays in its proper supporting role.
Use lookup from Nmap. The official lookup-disclose.nse integration enriches public scan targets with bounded reporting routes while refusing private targets, limiting scan-wide requests, and keeping optional API keys out of output.
The guide and visual theme now carry across the whole site. A dedicated usage guide explains input types and precise prefixes, while shared navigation and light/dark controls now behave consistently on lookup, guide, how-it-works, and changelog pages.
Coordinator routes are no longer described as no route. The human-facing fallback status now says No first-party reporting route found, preserving the distinction between an absent owner-published channel and a valid CERT or CNA coordination route.
Fallback email order now matches reporting intent. When only otherwise-equivalent, unverified convention addresses are available, security@ comes before abuse@. Published and owner-authorized routes still come first. The guides now explain that distinction, the party-first ordering model, and why an exact affected asset produces a clearer answer than a broad organization name.
Current first-party programs outrank stale catalogs. When a site's current, unexpired security.txt names its disclosure platform, lookup now removes conflicting program links from older third-party catalogs while retaining every platform the site explicitly publishes. Missing, expired, or custom-portal-only policies do not trigger that suppression.
Hosted SaaS tenants no longer inherit their provider's owner. Customer instances under documented shared service namespaces keep their full hostname and run only tenant-safe checks. The platform operator can still appear as hosting context, but its corporate metadata and bug-bounty program cannot become the customer's owner or reporting route.
Reference data now refreshes itself — with a human gate. The official CVE CNA roster and Cloudflare origin ranges are checked weekly. Schema, coverage, and suspicious-shrinkage checks run before an update can become a reviewable pull request; the job never deploys straight to production.
Security.txt now reports what the site actually publishes. A TLS hostname edge case made valid files look missing on sites including Google, HackerOne, and Bugcrowd. lookup now reaches the standard /.well-known/security.txt location before the root fallback, distinguishes an inaccessible probe from a real absence, and keeps expired files visible without treating them as current authority.
The answer is now the first thing you see. Results put reporting contacts before attribution and the evidence chain, so the route to the security team is immediate while the reasoning remains one section away. The search page also explains that specific identifiers produce the best result, and the navigation stays legible on a narrow viewport.
CVE coordination is useful without stealing the headline. Exact organization matches can now surface their official CVE Numbering Authority intake and scope. A direct, unresolved organization query can reach the CNA of Last Resort, but every owner, vendor, or maintainer channel remains above it — and the universal CERT backstop remains last.
Traffic spikes fail fast instead of taking the service down. Duplicate searches share one live lookup, HTTP and MCP reuse the same result cache, and excess unique work receives a clear, retryable busy response rather than accumulating an unbounded queue.
Official container images route to the software's owner, not its packager. Looking up a Docker Official Image now reaches the upstream project's security channel: mysql:8 resolves to Oracle's PSIRT, debian:12 surfaces [email protected], and Docker's own packaging contacts stay listed for image-build issues. Previously every official image stopped at the curator.
Name-squatting add-ons can no longer speak for a brand. Extension lookups matched loosely against add-on store listings, so a handful-of-users clone could answer for Microsoft Editor or Notion Web Clipper and route a vulnerability report to a stranger. Matches now require the exact name plus real adoption, and the big brands are pinned to their true owners.
Multi-word device makers resolve whole. Raspberry Pi 4 is no longer attributed to "Raspberry", and Western Digital My Cloud now finds Western Digital's actual vulnerability disclosure program and PSIRT instead of a one-word dead end.
Every legally-shaped FCC ID now reaches the registry. Longer modern FCC IDs (like the ESP32's 2AC7Z-ESP32WROOM32E) were being mistaken for product names and echoed back as the "owner". The full legal shape is recognized, and Raspberry Pi's grantee code joined the seed, so those devices resolve to their real manufacturers.
Bring lookup into the tools you already use. Four official integrations — all thin clients over the same live API, now linked from an Integrations section on the home page: dio-lookup, a pipe-friendly Unix CLI (npm i -g dio-lookup or bunx dio-lookup, stdin → JSONL); a Caido plugin for context-menu and sidebar lookups; a Burp Suite extension for right-click host lookups; and a Chrome extension showing the disclosure posture of the tab you're on. Each ships with installable releases on GitHub under github.com/disclose.
A "verified" link never dead-ends. An upstream data feed was quietly corrupting some bug-bounty program URLs; lookup now normalizes and validates every contact URL before it's shown, so a link marked verified actually resolves — regardless of what upstream sends.
The organization's own channel ranks first. Looking up a parent company no longer puts a subsidiary's bug bounty above the org's own PSIRT — cisco.com now leads with [email protected], with the Meraki program listed after it as a subsidiary channel, and the same rule carries any sub-brand.
Personal profiles aren't project channels. A maintainer's personal bug-bounty profile no longer surfaces as a project's official reporting channel, and a personal repository is no longer attributed to its owner's employer just because that employer appears on their profile.
Store listings can't hijack ownership. When a project's listed homepage is an app-store page (Chrome Web Store, App Store, and friends), lookup no longer follows it into attributing the project to Google, Apple, or Microsoft — the store is where it's hosted, not who owns it.
Fewer wrong-domain guesses for company names. Name-to-domain matches drawn from public knowledge bases now carry the same skepticism as plain lexical guesses, so a company no longer resolves to an unrelated foreign homonym's domain. And a package owned by a GitHub organization now names that organization as the owner instead of leaving attribution blank.
Accuracy is now audited continuously — and your feedback feeds it. lookup regularly re-checks a sample of its own "complete" answers against live sources to catch quiet regressions, and the in-result "flag this" feedback flows straight into that audit loop. The feedback endpoint was also hardened for privacy — it stores references, not payloads.
Hardening under the hood. Outbound fetches are now guarded against server-side request forgery (private and reserved addresses re-checked at every hop, no blind redirect-following), operational endpoints require authentication, and rate limiting fails closed instead of open.
More countries get their own national CERT. When an asset has no published security contact, lookup falls back to the right national CSIRT for its country. That backstop now covers seven more jurisdictions — Kazakhstan, Türkiye, Saudi Arabia, Argentina, Egypt, Iceland, and Serbia — so a site like centernur.kz routes to KZ-CERT instead of a generic global coordinator. Each added CERT was verified against its official source; none are guessed.
One-word lookups no longer mis-attribute — and hint at packages. A bare term like react is no longer pinned to an unrelated company that merely shares the name; lookup only attributes a one-word search to a company whose name actually matches it. And when a one-word search looks like a software package, lookup now suggests the precise form to use — e.g. npm:react or pypi:lodash — instead of guessing which package or company you meant.
Browser extensions resolve to the real vendor — dynamically. Paste a Chrome/Firefox/Edge store URL, or use ext:chrome:<id> / ext:firefox:<slug> / ext:name, and lookup identifies the owning project or company and then fetches that vendor's live security channel — the same security.txt / PSIRT / bug-bounty machinery used everywhere else, so the contact is always current (live hackerone.com/bitwarden, bugcrowd.com/lastpass, and so on). The browser-store address is a last-resort fallback, not the answer. Well-known vendors resolve with no fixed entry at all; only collision-prone names a lexical lookup would get wrong are disambiguated — Dark Reader (not Netflix), Honey → PayPal, uBlock Origin → its individual author.
More accurate ownership for packages & repositories. A package or repo is no longer attributed to GitHub or Microsoft just because its code is hosted there; contact extraction is tighter (no more prose bleeding into email addresses, no admin/settings links, no unrelated foundation contacts), and a CERT-only result is honestly flagged as "no direct owner contact found".
npm packages resolve to the real maintainer or vendor. Looking up npm:<package> follows the package's own registry and repository metadata to its project or company instead of collapsing to GitHub or npm just because that's where the code and registry live. It's a general rule — not a per-package list — so vue resolves to Vue, @angular/core to Google, webpack to the webpack project, and the same logic carries any other package. Maintainer-led packages with no published security policy surface the project's GitHub private-vulnerability-reporting channel, and a maintainer's personal or university email no longer drags in an unrelated company's contacts.
Scoped npm packages resolve without the npm: prefix. Paste a bare scoped package like @aws-sdk/client-s3 or @angular/core and lookup now recognizes it as the npm package it is — resolving to the real owner's security channel (AWS's bug bounty, Google's reporting) — instead of treating it as an unknown organization and falling back to a generic national-CERT coordinator. The explicit npm:@scope/name form keeps working exactly as before.
Hardware & FCC IDs resolve to the real manufacturer. An FCC ID like hw:BCG-E2599A now resolves through its grantee code to the actual maker (Apple), then to that vendor's live security channel — instead of treating the opaque ID as a company and inventing a psirt@<id>.com address. When a device's manufacturer can't be confidently resolved, lookup says so honestly rather than fabricating a contact or a generic FIRST.org search link.
Container images resolve to the right vendor. Point lookup at an image from any major registry — Docker Hub, GHCR, GitLab, Quay, Microsoft (MCR), Google (GCR & Artifact Registry), Amazon ECR Public, Kubernetes, Chainguard, NVIDIA, Red Hat, Elastic, SUSE — and it routes the registry host to its operator, then fetches that operator's live security contact (no contacts are baked in). Docker Official Images like nginx and postgres now route to Docker instead of a mystery "library" org, and a private registry honestly reports "no direct owner contact" instead of looking like a partial win.
Contacts grouped by who you'd report to. Results now cluster every reporting channel under the party it reaches — the maintainer, the hosting platform, its parent company — strongest channel first, with a national-CERT backstop always last. A "How we order contacts" note explains the order.
Look up an organization by name. Search a company or product — e.g. Stripe or Figma — and get its security-reporting channels, not just domains and IPs.
Clearer handling of private & invalid inputs. Private and loopback addresses, and obviously-malformed inputs, now return a purposeful explanation instead of an empty result.
Optional free API keys. Higher rate limits for heavy users and integrations. The anonymous tier stays free, with no signup.
Hosted MCP server, now in the official registry. Connect lookup to Claude, Cursor, and other AI agents in a single step.
Snappier, more reliable results. Large lookups that could occasionally stall now return promptly with the contacts found.
A home for developers & AI agents. Copy-paste API examples on the site, plus an llms.txt so coding agents can integrate in one shot.
Organization → domain resolution. A company name now resolves to its official domain and the security contacts behind it.
JSON API with full docs. An OpenAPI 3.1 spec and an interactive /api-docs explorer, with stable responses and per-request IDs.
Faster repeats & fair-use limits. Cached responses for repeat lookups and clear rate-limit headers.
Primary vs. fallback contacts. Results now separate strong reporting channels — bug bounty, security.txt, VDP — from fallbacks like abuse and national CERT.
Wider national-CERT coverage. More countries covered as a backstop when no direct channel exists.
Find the security team even when there's no security channel. When an organization is identified but exposes no security contact, results now offer a one-click LinkedIn people search for security staff at that company — a human fallback instead of a dead end. Idea credit: @insiderphd.
Homepage examples show what they are. The example chips on the homepage now name the asset type — Domain, IP Address, GitHub Repo, and so on — instead of showing a raw sample value.
Predictable responses & errors. Every request now carries an X-Request-Id echoed back for support correlation, failures return a structured JSON error envelope instead of leaking a plain-text default, and the result status vocabulary is stabilized: complete, partial, failed, rate_limited, not_found, error.
Smaller web polish. Keyboard shortcuts no longer steal focus while you're typing feedback, and the logo reliably returns you home with a cleared search.
More programs found. Broader bug-bounty and VDP coverage, plus subdomain discovery, for fewer "no program found" misses.
Follows corporate structure & rebrands. Resolves parent/subsidiary relationships and renamed or aliased domains.
Hardware by FCC ID. Identify a device's manufacturer and how to reach their security team.
Sharper attribution. Fewer mistaken matches at messy corporate boundaries.
AI-agent support. The first Model Context Protocol (MCP) server.
A rebuilt resolution engine. Follows the trail across sources: a package → its repository → the owning organization → its published security.txt.
Many more sources. Package-maintainer contacts, IP and network ownership, certificate data, and more.
Tell us when we're wrong. In-result feedback to flag a bad attribution or a missing channel.
A clearer result view. Line-art icons and a visual chain showing how each answer was reached.
lookup.disclose.io is born. One question kept stalling vulnerability reports: "who do I even tell?" lookup answers it — give it a domain, IP, URL, or email and it finds the right security-disclosure contact.