Qi Anxin · Vulnerability Disclosure
Qi Anxin Vulnerability Disclosure
Vulnerability disclosure
Qi Anxin runs a coordinated vulnerability disclosure program on Hackerone.
CompanySecurityCybersecurityThreat IntelligenceEndpoint SecurityNetwork SecurityVulnerability ManagementMCPChina
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-26'
method: searched
source: https://www.butian.net/, https://qianxin.butian.net/, https://www.qianxin.com/product/detail/pid/451;
probed 2026-08-26
program: Butian Vulnerability Response Platform (补天漏洞响应平台)
operated_by: Qi An Xin Technology Group (QAX)
public_submission: true
summary: 'QAX operates Butian, a public vulnerability response platform with an open
researcher-submission flow (提交漏洞), a reviewing team, and a cash reward and ranking
programme for white-hat researchers. It is both QAX''s own disclosure channel and
the SRC-hosting product QAX sells to other organisations; QAX runs its own presence
on it at qianxin.butian.net.'
channels:
- kind: vulnerability-response-platform
url: https://www.butian.net/
http_status: 200
probed: '2026-08-26'
note: Public submission platform operated by QAX. Accepts system, IoT, mobile app,
industrial-control, AI and large-model security vulnerabilities.
- kind: qax-presence
url: https://qianxin.butian.net/
http_status: 200
probed: '2026-08-26'
note: QAX's own tenant on the Butian platform.
- kind: product-page
url: https://www.qianxin.com/product/detail/pid/451
probed: '2026-08-26'
note: 补天全栈式SRC服务 — the QAX product page describing the full-stack SRC service.
- kind: email
value: ti_support@qianxin.com
note: Threat-intelligence platform support contact (API access), not a dedicated
security-report address.
rewards:
offered: true
kind: cash + ranking recognition
amounts_published: false
note: The platform publicises monthly white-hat rankings and annual cash awards;
per-report bounty tables were not readable from a non-authenticated fetch.
scope_published: true
scope: system vulnerabilities, IoT, mobile applications, industrial control systems,
AI security, large-language-model security
safe_harbour_published: unknown
disclosure_timeline_published: unknown
security_txt:
served: false
note: No RFC 9116 /.well-known/security.txt on any QAX host — see well-known/qi-anxin-well-known.yml.
The disclosure route is a web platform, not a machine-discoverable security.txt.
third_party_bounty_platforms:
hackerone: not found
bugcrowd: not found
intigriti: not found
note: QAX runs its own platform rather than using a Western bounty host, which is
why the automated probe (probe-security-programs.py, which looks for security.txt
plus HackerOne/Bugcrowd/Intigriti) returned vdp=none. Recorded here by manual search.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/qi-anxin-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.