ReviewTrackers · Vulnerability Disclosure

Reviewtrackers Vulnerability Disclosure

Vulnerability disclosure

ReviewTrackers runs a self-hosted bug bounty program with a published policy page, a named security contact, and an explicit in-scope target list that includes the production API host. There is no security.txt on any host — the policy is published only as an HTML page.

ReviewTrackers runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Reputation ManagementReview MonitoringCustomer FeedbackSentiment AnalyticsLocal SEOOnline ReviewsMulti-LocationCustomer ExperienceReview ResponseLocal Listings
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@reviewtrackers.com

Source

Vulnerability Disclosure

reviewtrackers-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.reviewtrackers.com/bug-bounty/
name: ReviewTrackers Vulnerability Disclosure and Bug Bounty
description: >-
  ReviewTrackers runs a self-hosted bug bounty program with a published policy
  page, a named security contact, and an explicit in-scope target list that
  includes the production API host. There is no security.txt on any host — the
  policy is published only as an HTML page.
program:
  type: self-hosted
  platform: null
  platform_note: Not run on HackerOne, Bugcrowd or Intigriti — ReviewTrackers accepts reports directly.
  rewards: true
  reward_detail: Monetary awards paid, amount dependent on severity. No published bounty table.
policy:
  - https://www.reviewtrackers.com/bug-bounty/
contact:
  - security@reviewtrackers.com
scope:
  in_scope:
    - target: reviewtrackers.com
      type: website
    - target: app.reviewtrackers.com
      type: website
    - target: admin.reviewtrackers.net
      type: website
    - target: api.reviewtrackers.com
      type: api
    - target: ReviewTrackers iOS application
      type: mobile
    - target: ReviewTrackers Android application
      type: mobile
  out_of_scope:
    - Any ReviewTrackers domain or property not named in the targets list.
    - Third-party services.
    - Signing up for new accounts or requesting free trials as part of testing.
    - Testing contact and feedback form functionality.
  focus_areas:
    - Unauthorized access to other users' data
    - SQL injection
safe_harbor:
  published: true
  requirements:
    - Allow reasonable investigation time before public disclosure.
    - Do not access or modify other users' accounts or data without permission.
    - Do not violate privacy.
    - Do not exploit a discovered vulnerability beyond proof of existence.
    - Comply with applicable law.
  response_sla: null
security_program:
  penetration_testing: Annual third-party penetration testing; certificate of results available on request via account manager.
  vulnerability_scanning: Daily comprehensive security scan with alerting on the application and website.
  password_storage: bcrypt
  cyber_insurance: true
  employee_screening: Background and reference checks, confidentiality agreements, recurring security training, 90-day password rotation.
  source: https://www.reviewtrackers.com/terms-service/security/
evidence:
  - source: https://www.reviewtrackers.com/bug-bounty/
    kind: bug-bounty-policy
    http_status: 200
  - source: https://www.reviewtrackers.com/terms-service/security/
    kind: security-page
    http_status: 200
    keywords: [bug bounty, penetration testing, bcrypt, cyber insurance]
  - source: https://api.reviewtrackers.com/.well-known/security.txt
    kind: security.txt
    http_status: 404
    result: not served
notes:
  - >-
    No RFC 9116 security.txt is served on any ReviewTrackers host. Publishing one at
    /.well-known/security.txt pointing Contact at security@reviewtrackers.com and
    Policy at the bug bounty page would make this program machine-discoverable.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/reviewtrackers-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.