Swetrix · Vulnerability Disclosure

Swetrix Vulnerability Disclosure

Vulnerability disclosure

Swetrix runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

AnalyticsCookieless TrackingGDPR CompliantOpen-SourcePrivacyReal-Time AnalyticsWeb Analytics
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@swetrix.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://swetrix.com/security
policy:
  - https://swetrix.com/security
contact:
  - security@swetrix.com
bug_bounty:
  program: null
  platform: null
  note: >-
    No bug bounty. Searched HackerOne, Bugcrowd and Intigriti references across
    swetrix.com on 2026-08-13 — none. Disclosure is a direct email invitation:
    "If you discover a vulnerability or have any security concerns, please report
    it to us directly so we can address it responsibly."
security_txt:
  published: false
  note: >-
    /.well-known/security.txt returns 404 on swetrix.com and api.swetrix.com
    (RFC 9116 not implemented). See well-known/swetrix-well-known.yml. The
    security contact is human-page-only, which means an automated scanner cannot
    find it.
disclosure_page:
  url: https://swetrix.com/security
  title: Security Practices
  last_updated: '2026-03-27'
  status: 200
published_controls:
  - Encryption in transit — enforced HTTPS with HSTS, X-Content-Type-Options, restrictive Referrer-Policy
  - Encryption at rest — bcrypt for passwords and 2FA recovery codes; AES-256-CBC + Rabbit for integration tokens
  - EU-only data residency (Germany, Hetzner Online GmbH)
  - Cookieless, salted-hash visitor counting with a daily rotating salt and raw inputs discarded
  - Two-factor authentication and SSO
  - Role-restricted internal access; no routine access to customer data
  - Named subprocessor list (Hetzner, Sentry, Paddle)
  - No card data stored — payments handled by Paddle
  - Public status page with historical uptime and incident reports
  - Full source-code auditability (AGPL-3.0)
evidence:
  - source: https://swetrix.com/security
    kind: disclosure page
    http_status: 200
    keywords:
      - vulnerability
      - security@
      - responsibly
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/swetrix-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.