Qi Anxin · Vulnerability Disclosure

Qi Anxin Vulnerability Disclosure

Vulnerability disclosure

Qi Anxin runs a coordinated vulnerability disclosure program on Hackerone.

CompanySecurityCybersecurityThreat IntelligenceEndpoint SecurityNetwork SecurityVulnerability ManagementMCPChina
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

qi-anxin-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-26'
method: searched
source: https://www.butian.net/, https://qianxin.butian.net/, https://www.qianxin.com/product/detail/pid/451;
  probed 2026-08-26
program: Butian Vulnerability Response Platform (补天漏洞响应平台)
operated_by: Qi An Xin Technology Group (QAX)
public_submission: true
summary: 'QAX operates Butian, a public vulnerability response platform with an open
  researcher-submission flow (提交漏洞), a reviewing team, and a cash reward and ranking
  programme for white-hat researchers. It is both QAX''s own disclosure channel and
  the SRC-hosting product QAX sells to other organisations; QAX runs its own presence
  on it at qianxin.butian.net.'
channels:
- kind: vulnerability-response-platform
  url: https://www.butian.net/
  http_status: 200
  probed: '2026-08-26'
  note: Public submission platform operated by QAX. Accepts system, IoT, mobile app,
    industrial-control, AI and large-model security vulnerabilities.
- kind: qax-presence
  url: https://qianxin.butian.net/
  http_status: 200
  probed: '2026-08-26'
  note: QAX's own tenant on the Butian platform.
- kind: product-page
  url: https://www.qianxin.com/product/detail/pid/451
  probed: '2026-08-26'
  note: 补天全栈式SRC服务 — the QAX product page describing the full-stack SRC service.
- kind: email
  value: ti_support@qianxin.com
  note: Threat-intelligence platform support contact (API access), not a dedicated
    security-report address.
rewards:
  offered: true
  kind: cash + ranking recognition
  amounts_published: false
  note: The platform publicises monthly white-hat rankings and annual cash awards;
    per-report bounty tables were not readable from a non-authenticated fetch.
scope_published: true
scope: system vulnerabilities, IoT, mobile applications, industrial control systems,
  AI security, large-language-model security
safe_harbour_published: unknown
disclosure_timeline_published: unknown
security_txt:
  served: false
  note: No RFC 9116 /.well-known/security.txt on any QAX host — see well-known/qi-anxin-well-known.yml.
    The disclosure route is a web platform, not a machine-discoverable security.txt.
third_party_bounty_platforms:
  hackerone: not found
  bugcrowd: not found
  intigriti: not found
  note: QAX runs its own platform rather than using a Western bounty host, which is
    why the automated probe (probe-security-programs.py, which looks for security.txt
    plus HackerOne/Bugcrowd/Intigriti) returned vdp=none. Recorded here by manual search.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/qi-anxin-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.