Awin · Vulnerability Disclosure

Awin Affiliate Vulnerability Disclosure

Vulnerability disclosure

Awin runs a private, invitation-based bug bounty on Intigriti and advertises it through an RFC 9116 security.txt served from three separate hosts. Researchers are asked to create an Intigriti account first and then email their @intigriti.me address to security-bugs@awin.com to be invited into the programme - so the programme itself is not publicly enumerable. The API host serves a DIFFERENT security.txt advertising an OpenBugBounty listing instead.

Awin runs a coordinated vulnerability disclosure program on Intigriti. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Affiliate MarketingAdvertisingPublishersAdvertisersTransactionReportingCommissionsPerformance Marketing
Program: Intigriti security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security-bugs@awin.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.awin.com/.well-known/security.txt
description: >-
  Awin runs a private, invitation-based bug bounty on Intigriti and advertises it
  through an RFC 9116 security.txt served from three separate hosts. Researchers
  are asked to create an Intigriti account first and then email their
  @intigriti.me address to security-bugs@awin.com to be invited into the
  programme - so the programme itself is not publicly enumerable. The API host
  serves a DIFFERENT security.txt advertising an OpenBugBounty listing instead.
program:
  type: private bug bounty
  platform: Intigriti
  platform_url: https://www.intigriti.com
  invitation_required: true
  invitation_process: >-
    Create an Intigriti account, then send your @intigriti.me address to
    security-bugs@awin.com to be invited into the programme.
policy:
- https://www.awin.com/.well-known/security.txt
policy_text: >-
  To submit your findings please set up an account with www.intigriti.com. After
  you're done, send us your @intigriti.me address to security-bugs@awin.com so we
  can invite you into the program.
contact:
- mailto:security-bugs@awin.com
additional_programs:
- platform: OpenBugBounty
  url: https://openbugbounty.org/bugbounty/infosec_jma/
  advertised_on: https://api.awin.com/.well-known/security.txt
  note: >-
    Only the API host advertises this. The www and ui hosts do not mention
    OpenBugBounty at all - the three published security.txt documents disagree
    with each other, which is worth flagging to Awin.
security_txt_hosts:
- host: https://www.awin.com
  status: 200
  fields: [Contact, Policy]
- host: https://api.awin.com
  status: 200
  fields: [Contact, OpenBugBounty]
- host: https://ui.awin.com
  status: 200
  fields: [policy text only - no Contact: field]
rfc9116_gaps:
- No Expires field on any of the three documents (mandatory in RFC 9116).
- No Encryption, Acknowledgments, Preferred-Languages or Canonical fields.
- The ui.awin.com document is free text with no field syntax at all.
evidence:
- source: https://www.awin.com/.well-known/security.txt
  kind: security.txt (live probe)
  http_status: 200
- source: https://api.awin.com/.well-known/security.txt
  kind: security.txt (live probe)
  http_status: 200
- source: https://ui.awin.com/.well-known/security.txt
  kind: security.txt (live probe)
  http_status: 200
- source: well-known/awin-affiliate-security.txt
  kind: saved verbatim
x-evidence:
  fetched: '2026-08-13'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/awin-affiliate-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.