Affise · Vulnerability Disclosure

Affise Vulnerability Disclosure

Vulnerability disclosure

Affise runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Affiliate MarketingPerformance MarketingConversionsPublishersAnalyticsAttribution
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:j.michael@affise.com
Contact
https://srs.s4e.io/affise.com/report

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://affise.com/.well-known/security.txt
note: >-
  Affise serves TWO different vulnerability-disclosure documents that name TWO different
  contacts, and a researcher following the standard is sent to the stale one. The
  canonical RFC 9116 path, /.well-known/security.txt, returns 200 but carries
  `Expires: 2025-01-16T15:08:00.000Z` — more than eighteen months before this probe, which
  makes it formally stale under RFC 9116 section 2.5.5 — and points at a single personal
  mailbox. A second, more complete file sits at the non-canonical site root /security.txt,
  published through the S4E disclosure service with a report form and an acknowledgements
  page, but it has no Expires field and is not where a scanner looks. There is no
  security or responsible-disclosure page on affise.com itself
  (affise.com/security/ returns 404), and no public bug-bounty program on HackerOne,
  Bugcrowd or Intigriti was found. The single highest-value fix here costs one line:
  refresh /.well-known/security.txt with a current Expires and the S4E report URL.
policy:
  - https://srs.s4e.io/affise.com/report
contact:
  - mailto:j.michael@affise.com
  - https://srs.s4e.io/affise.com/report
acknowledgments:
  - https://srs.s4e.io/affise.com
preferred_languages: en
bug_bounty:
  program: null
  platform: null
  note: 'No HackerOne, Bugcrowd or Intigriti program found. S4E provides an intake form, not a bounty.'
documents:
  - path: /.well-known/security.txt
    url: https://affise.com/.well-known/security.txt
    http_status: 200
    canonical: true
    file: well-known/affise-security.txt
    expires: '2025-01-16T15:08:00.000Z'
    expired: true
    contact: mailto:j.michael@affise.com
    fields_present: [Contact, Expires]
    fields_missing: [Policy, Acknowledgments, Preferred-Languages, Encryption, Canonical]
  - path: /security.txt
    url: https://affise.com/security.txt
    http_status: 200
    canonical: false
    file: well-known/affise-security-root.txt
    contact: https://srs.s4e.io/affise.com/report
    acknowledgments: https://srs.s4e.io/affise.com
    provider: S4E (srs.s4e.io)
    fields_present: [Contact, Acknowledgments, Preferred-Languages]
    fields_missing: [Expires, Policy]
evidence:
  - source: https://affise.com/.well-known/security.txt
    kind: security.txt
    http_status: 200
    fetched: '2026-08-13'
  - source: https://affise.com/security.txt
    kind: security.txt (root path)
    http_status: 200
    fetched: '2026-08-13'
  - source: https://srs.s4e.io/affise.com/report
    kind: disclosure intake form
    http_status: 200
    fetched: '2026-08-13'
  - source: https://affise.com/security/
    kind: security page
    http_status: 404
    fetched: '2026-08-13'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/affise-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.