Affise · Vulnerability Disclosure

Affise Vulnerability Disclosure

Vulnerability disclosure

Affise runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Affiliate MarketingPerformance MarketingConversionsPublishersAnalyticsAttribution
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:j.michael@affise.com
Contact
https://srs.s4e.io/affise.com/report

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://affise.com/.well-known/security.txt
note: >-
  Affise serves TWO different vulnerability-disclosure documents that name TWO different
  contacts, and a researcher following the standard is sent to the stale one. The
  canonical RFC 9116 path, /.well-known/security.txt, returns 200 but carries
  `Expires: 2025-01-16T15:08:00.000Z` — more than eighteen months before this probe, which
  makes it formally stale under RFC 9116 section 2.5.5 — and points at a single personal
  mailbox. A second, more complete file sits at the non-canonical site root /security.txt,
  published through the S4E disclosure service with a report form and an acknowledgements
  page, but it has no Expires field and is not where a scanner looks. There is no
  security or responsible-disclosure page on affise.com itself
  (affise.com/security/ returns 404), and no public bug-bounty program on HackerOne,
  Bugcrowd or Intigriti was found. The single highest-value fix here costs one line:
  refresh /.well-known/security.txt with a current Expires and the S4E report URL.
policy:
  - https://srs.s4e.io/affise.com/report
contact:
  - mailto:j.michael@affise.com
  - https://srs.s4e.io/affise.com/report
acknowledgments:
  - https://srs.s4e.io/affise.com
preferred_languages: en
bug_bounty:
  program: null
  platform: null
  note: 'No HackerOne, Bugcrowd or Intigriti program found. S4E provides an intake form, not a bounty.'
documents:
  - path: /.well-known/security.txt
    url: https://affise.com/.well-known/security.txt
    http_status: 200
    canonical: true
    file: well-known/affise-security.txt
    expires: '2025-01-16T15:08:00.000Z'
    expired: true
    contact: mailto:j.michael@affise.com
    fields_present: [Contact, Expires]
    fields_missing: [Policy, Acknowledgments, Preferred-Languages, Encryption, Canonical]
  - path: /security.txt
    url: https://affise.com/security.txt
    http_status: 200
    canonical: false
    file: well-known/affise-security-root.txt
    contact: https://srs.s4e.io/affise.com/report
    acknowledgments: https://srs.s4e.io/affise.com
    provider: S4E (srs.s4e.io)
    fields_present: [Contact, Acknowledgments, Preferred-Languages]
    fields_missing: [Expires, Policy]
evidence:
  - source: https://affise.com/.well-known/security.txt
    kind: security.txt
    http_status: 200
    fetched: '2026-08-13'
  - source: https://affise.com/security.txt
    kind: security.txt (root path)
    http_status: 200
    fetched: '2026-08-13'
  - source: https://srs.s4e.io/affise.com/report
    kind: disclosure intake form
    http_status: 200
    fetched: '2026-08-13'
  - source: https://affise.com/security/
    kind: security page
    http_status: 404
    fetched: '2026-08-13'