Ajaib · Vulnerability Disclosure

Ajaib Vulnerability Disclosure

Vulnerability disclosure

Ajaib publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyFinancial ServicesInvestingBrokerageTradingCryptocurrencyCrypto ExchangeStocksMutual FundsFintechIndonesiaWealth Management
Program: security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@ajaib.co.id

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-06'
method: probed
probe: true
source: https://ajaib.co.id/
policy: []
contact:
- mailto:security@ajaib.co.id
rewards: true
discovery:
  mechanism: http-response-headers
  note: >-
    Ajaib does not publish an RFC 9116 /.well-known/security.txt (404 on every
    Ajaib host) and no responsible-disclosure page could be read. Instead, every
    Ajaib origin advertises its security contact and the existence of a rewards
    programme in custom HTTP response headers on every response, including the
    Cloudflare 403 challenge page.
headers:
- name: x-security-bugs-report
  value: security@ajaib.co.id
- name: x-security-bugs-rewards
  value: 'true'
evidence:
- source: https://ajaib.co.id/
  kind: http-response-header
  http_status: 403
  headers_observed: [x-security-bugs-report, x-security-bugs-rewards]
  fetched: '2026-08-06'
- source: https://kripto.ajaib.co.id/
  kind: http-response-header
  http_status: 403
  headers_observed: [x-security-bugs-report, x-security-bugs-rewards]
  fetched: '2026-08-06'
- source: https://api.ajaib.co.id/
  kind: http-response-header
  http_status: 403
  headers_observed: [x-security-bugs-report, x-security-bugs-rewards]
  fetched: '2026-08-06'
- source: https://ajaib.co.id/.well-known/security.txt
  kind: security.txt (live probe)
  http_status: 404
  result: absent
gaps:
- >-
  No /.well-known/security.txt. The same two facts Ajaib already serves in
  custom headers (security@ajaib.co.id, a rewards programme) would satisfy RFC
  9116 Contact: and Policy: fields and be found by every standard scanner.
- >-
  No public disclosure policy page, no scope statement, no safe-harbour
  language, and no named bug-bounty platform, so a reporter cannot tell what is
  in scope or what protection they have.