AnyAPI · Vulnerability Disclosure

Anyapi Vulnerability Disclosure

Vulnerability disclosure

AnyAPI runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

developer_toolsdatasearchscrapingsocial_mediaecommerceseoenrichmentmcpagent-nativeweb-dataapi-marketplaceagent-paymentsx402
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
support@getanyapi.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-04'
method: searched
probe: true
source: https://getanyapi.com/security
note: >-
  probe-security-programs.py found nothing because getanyapi.com is a client-rendered Next.js
  site and the disclosure text is not in the raw HTML the probe reads. A rendered fetch of the
  same URL returns a real "Security and trust" page, last updated June 23 2026, whose section 6
  is headed "Reporting a vulnerability". It is minimal - a mailbox and nothing else - and is
  recorded at exactly that strength.
policy: [https://getanyapi.com/security]
contact: [support@getanyapi.com]
policy_text: 'Reporting a vulnerability: Report security issues to support@getanyapi.com'
last_updated: '2026-06-23'
bug_bounty:
  present: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
security_txt:
  present: false
  probed:
    - {url: 'https://getanyapi.com/.well-known/security.txt', status: 404}
    - {url: 'https://api.getanyapi.com/.well-known/security.txt', status: 404}
    - {url: 'https://www.getanyapi.com/.well-known/security.txt', status: 404}
  note: >-
    The one clear gap. The provider has a disclosure contact and a page to put it on; adding an
    RFC 9116 /.well-known/security.txt with Contact and Policy lines would make it machine-
    discoverable at no cost.
disclosure_terms:
  safe_harbor: not stated
  response_sla: not stated
  scope: not stated
  note: No timeline, no safe-harbor language and no scope definition are published.
evidence:
  - {source: 'https://getanyapi.com/security', kind: disclosure-page, http_status: 200, section: '6. Reporting a vulnerability'}
other_security_statements:
  - 'Payments are handled by third-party payment processors. AnyAPI does not store full card numbers.'
  - 'API keys and account sessions authenticate all requests; keep them confidential and revoke compromised keys in the dashboard.'
  - 'You decide what the Service retrieves; we act on your instructions. We process request parameters and returned data only to provide the Service.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/anyapi-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.