AppsMax · Vulnerability Disclosure

Appsmax Rest Api V1 Vulnerability Disclosure

Vulnerability disclosure

AppsMax runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySaaSMessagingBusiness AutomationChatbotsMini AppsCustomer RequestsWorkflow AutomationMAXTelegramRussian Language
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
https://appsmax.ru/contacts/
Contact
info@appsmax.ru

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-09'
method: searched
probe: true
source: https://gitverse.ru/appsmax/appsmax-api-reference

published: true
policy:
  - https://gitverse.ru/appsmax/appsmax-api-reference   # SECURITY.md in the provider's own public reference repo
contact:
  - https://appsmax.ru/contacts/
  - info@appsmax.ru

local_copy: security/appsmax-rest-api-v1-security-policy.md

policy_summary: >-
  AppsMax publishes a SECURITY.md in its own public API-reference repository on GitVerse. It
  asks reporters NOT to publish a live vulnerability or affected-user data in a public issue,
  and to send a short description through the official contact channel instead. A first report
  should name the affected component, the expected and actual behaviour, and safe reproduction
  steps, and must not attach API tokens, passwords, personal data or production exports. The
  repository scope is explicitly limited to the public reference — documentation errors may be
  discussed publicly as long as the message does not disclose secrets, personal data or a
  working exploit path.

token_handling_guidance:
  - Store the token only server-side in a secret store.
  - Issue the minimum required scopes.
  - Never place the token in a repository, browser code, mobile app, URL, screenshot or ordinary email.
  - Revoke and reissue on any suspicion of disclosure.
  - Do not publish working payloads that contain personal data.

bug_bounty:
  program: false
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program was found.

security_txt:
  published: false
  probed:
    - url: https://appsmax.ru/.well-known/security.txt
      status: 404
    - url: https://telegram.appsmax.ru/.well-known/security.txt
      status: 404
  note: >-
    The disclosure policy exists but is not reachable at the RFC 9116 well-known path. Serving
    the same contact at https://appsmax.ru/.well-known/security.txt would make it machine-discoverable.

evidence:
  - source: https://gitverse.ru/appsmax/appsmax-api-reference
    kind: SECURITY.md
    http_status: 200
  - source: https://appsmax.ru/developers/
    kind: security-and-limits section
    http_status: 200

x-evidence:
  fetched: '2026-08-09'
  urls:
    - url: https://gitverse.ru/appsmax/appsmax-api-reference
      http_status: 200
    - url: https://appsmax.ru/.well-known/security.txt
      http_status: 404