Pabbly · Vulnerability Disclosure

Pabbly Vulnerability Disclosure

Vulnerability disclosure

Pabbly runs a coordinated vulnerability disclosure program on Hackerone.

AutomationEmail MarketingSubscription BillingBillingPaymentsWebhookMessagingWhatsAppEmail VerificationFormsNo-CodeSoftware-as-a-Service
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

pabbly-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.pabbly.com/security-vulnerability-disclosure/
provider: Pabbly
providerId: pabbly
program:
  published: true
  name: Pabbly Security Vulnerability Disclosure Program
  url: https://www.pabbly.com/security-vulnerability-disclosure/
  mirror: https://buy.pabbly.com/security-vulnerability-disclosure/
  type: responsible-disclosure
  platform: self-hosted
  bug_bounty_platform: null
  note: >-
    Not on HackerOne, Bugcrowd or Intigriti — Pabbly runs the program itself and
    takes reports through its own form.
reporting:
  form: https://forms.pabbly.com/form/share/DPHw-722603307
  email_published: true
  email_obfuscated: true
  email_note: >-
    A reporting address is published on the page but is Cloudflare
    email-obfuscated in the markup, so it is not recorded verbatim here.
  security_txt: false
  security_txt_note: >-
    /.well-known/security.txt returned 404 on every Pabbly host — the program
    exists but is not machine-discoverable (see well-known/pabbly-well-known.yml).
scope:
  in_scope:
    - Pabbly web applications and services
  out_of_scope:
    - https://pabbly.hellonext.co
    - https://forum.pabbly.com
  qualifying:
    - authentication flaws
    - cross-site scripting (XSS)
    - server-side code execution
    - CORS / CSRF issues
  non_qualifying:
    - cookie flag issues
    - SPF / DKIM / DMARC configuration reports
    - denial-of-service attacks
safe_harbor:
  published: true
  language: >-
    "Do not cause any harm, hinder application fluency or act against our Terms
    of Use Agreement." Researchers must not access non-public data beyond what is
    needed to demonstrate the issue and must follow responsible disclosure.
response_commitment:
  acknowledgement: >-
    "We answer all submissions within a few days."
  fix_timeline: >-
    "Timelines for fixes will vary with the severity of the vulnerability and
    availability of engineering resources to address it."
rewards:
  offered: true
  discretionary: true
  maximum: 50
  currency: USD
  criteria:
    - severity
    - impact
    - originality
  payout_method: PayPal, after the fix ships, minus processing fees
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pabbly-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.