Awin · Vulnerability Disclosure
Awin Affiliate Vulnerability Disclosure
Vulnerability disclosure
Awin runs a private, invitation-based bug bounty on Intigriti and advertises it through an RFC 9116 security.txt served from three separate hosts. Researchers are asked to create an Intigriti account first and then email their @intigriti.me address to security-bugs@awin.com to be invited into the programme - so the programme itself is not publicly enumerable. The API host serves a DIFFERENT security.txt advertising an OpenBugBounty listing instead.
Awin runs a coordinated vulnerability disclosure program on Intigriti. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Affiliate MarketingAdvertisingPublishersAdvertisersTransactionReportingCommissionsPerformance Marketing
Program: Intigriti
security.txt present
Disclosure Policy
Security Contact
Contact
mailto:security-bugs@awin.com
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.