AppsMax · Vulnerability Disclosure

Appsmax Rest Api V1 Vulnerability Disclosure

Vulnerability disclosure

AppsMax runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySoftware-as-a-ServiceMessagingBusiness AutomationChatbotsMini AppsCustomer RequestsWorkflow-AutomationMAXTelegramRussian Language
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
https://appsmax.ru/contacts/
Contact
info@appsmax.ru

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-09'
method: searched
probe: true
source: https://gitverse.ru/appsmax/appsmax-api-reference

published: true
policy:
  - https://gitverse.ru/appsmax/appsmax-api-reference   # SECURITY.md in the provider's own public reference repo
contact:
  - https://appsmax.ru/contacts/
  - info@appsmax.ru

local_copy: security/appsmax-rest-api-v1-security-policy.md

policy_summary: >-
  AppsMax publishes a SECURITY.md in its own public API-reference repository on GitVerse. It
  asks reporters NOT to publish a live vulnerability or affected-user data in a public issue,
  and to send a short description through the official contact channel instead. A first report
  should name the affected component, the expected and actual behaviour, and safe reproduction
  steps, and must not attach API tokens, passwords, personal data or production exports. The
  repository scope is explicitly limited to the public reference — documentation errors may be
  discussed publicly as long as the message does not disclose secrets, personal data or a
  working exploit path.

token_handling_guidance:
  - Store the token only server-side in a secret store.
  - Issue the minimum required scopes.
  - Never place the token in a repository, browser code, mobile app, URL, screenshot or ordinary email.
  - Revoke and reissue on any suspicion of disclosure.
  - Do not publish working payloads that contain personal data.

bug_bounty:
  program: false
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program was found.

security_txt:
  published: false
  probed:
    - url: https://appsmax.ru/.well-known/security.txt
      status: 404
    - url: https://telegram.appsmax.ru/.well-known/security.txt
      status: 404
  note: >-
    The disclosure policy exists but is not reachable at the RFC 9116 well-known path. Serving
    the same contact at https://appsmax.ru/.well-known/security.txt would make it machine-discoverable.

evidence:
  - source: https://gitverse.ru/appsmax/appsmax-api-reference
    kind: SECURITY.md
    http_status: 200
  - source: https://appsmax.ru/developers/
    kind: security-and-limits section
    http_status: 200

x-evidence:
  fetched: '2026-08-09'
  urls:
    - url: https://gitverse.ru/appsmax/appsmax-api-reference
      http_status: 200
    - url: https://appsmax.ru/.well-known/security.txt
      http_status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/appsmax-rest-api-v1-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.