Tvarka ATK API · Vulnerability Disclosure

Tvarka Atk Api Vulnerability Disclosure

Vulnerability disclosure

Tvarka ATK API runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AuthenticationDigital SignatureeIDASQESLithuaniaOpenAPIeIDSmart-IDMobile-IDNFCTimestampingLTVWebhookIdentityTrust ServicesGDPR
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://tvarka.pro/kontaktai/
Contact
info@tvarka.pro

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-31'
method: searched
probe: true
source: https://tvarka.pro/saugumas/
policy:
  - https://tvarka.pro/saugumas/
contact:
  - https://tvarka.pro/kontaktai/
  - info@tvarka.pro
security_txt: true
security_txt_file: well-known/tvarka-security.txt
security_txt_url: https://tvarka.pro/.well-known/security.txt
bug_bounty: false
program:
  kind: informal-invitation
  statement_lt: >-
    "Pastebejote spraga? Jei radote saugumo problema ar turite klausimu apie duomenu apsauga,
    susisiekite - i saugumo pranesimus reaguojame pirmiausia."
  statement_en: >-
    "Spotted a vulnerability? If you found a security problem or have questions about data
    protection, get in touch - we respond to security reports first."
  note: >-
    A published, explicit invitation to report vulnerabilities on the provider's security page, with
    a stated response priority, NOW BACKED BY A MACHINE-READABLE RFC 9116 security.txt at
    https://tvarka.pro/.well-known/security.txt (200 on 2026-08-31; the same path 404d on
    2026-08-09). The security.txt names the same policy page and the same general mailbox. There is
    still no dedicated security@ address, no named response SLA and no bug-bounty program (no
    HackerOne / Bugcrowd / Intigriti presence found).
security_txt_fields:
  Contact: mailto:info@tvarka.pro
  Expires: '2027-08-30T00:00:00Z'
  Preferred-Languages: lt, en
  Canonical: https://tvarka.pro/.well-known/security.txt
  Policy: https://tvarka.pro/saugumas/
  note: >-
    Five fields, all valid, with a non-expired Expires. It is served only on the apex - the API hosts
    atk.tvarka.pro and sign-api.tvarka.pro both still 404 - which is acceptable under RFC 9116 for a
    single organisation but means a scanner pointed at the API host alone will miss it.
closed_since_previous_probe:
  - RFC 9116 security.txt is now published (was the top gap on 2026-08-09).
gaps:
  - No security.txt on the API hosts themselves, only on the apex domain.
  - No dedicated security contact address; reports go to the general info@ mailbox.
  - No published disclosure timeline or safe-harbour statement.
  - No Encryption or Acknowledgments field in the security.txt.
  - No bug-bounty or coordinated-disclosure program.
evidence:
  - {source: 'https://tvarka.pro/saugumas/', http_status: 200, kind: security-page, keywords: [saugumo problema, saugumo pranesimus, BDAR, eIDAS, QTSP, TLS]}
  - {source: 'https://tvarka.pro/kontaktai/', http_status: 200, kind: contact-page}
  - {source: 'https://atk.tvarka.pro/.well-known/security.txt', http_status: 404, kind: security.txt}
  - {source: 'https://tvarka.pro/.well-known/security.txt', http_status: 200, kind: security.txt, probed: '2026-08-31', note: 'was 404 on 2026-08-09'}
  - {source: 'https://sign-api.tvarka.pro/.well-known/security.txt', http_status: 404, kind: security.txt, probed: '2026-08-31'}
  - {source: 'https://atk.tvarka.pro/.well-known/security.txt', http_status: 404, kind: security.txt, probed: '2026-08-31'}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tvarka-atk-api-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.