generated: '2026-08-06' method: probed probe: true source: https://ajaib.co.id/ policy: [] contact: - mailto:security@ajaib.co.id rewards: true discovery: mechanism: http-response-headers note: >- Ajaib does not publish an RFC 9116 /.well-known/security.txt (404 on every Ajaib host) and no responsible-disclosure page could be read. Instead, every Ajaib origin advertises its security contact and the existence of a rewards programme in custom HTTP response headers on every response, including the Cloudflare 403 challenge page. headers: - name: x-security-bugs-report value: security@ajaib.co.id - name: x-security-bugs-rewards value: 'true' evidence: - source: https://ajaib.co.id/ kind: http-response-header http_status: 403 headers_observed: [x-security-bugs-report, x-security-bugs-rewards] fetched: '2026-08-06' - source: https://kripto.ajaib.co.id/ kind: http-response-header http_status: 403 headers_observed: [x-security-bugs-report, x-security-bugs-rewards] fetched: '2026-08-06' - source: https://api.ajaib.co.id/ kind: http-response-header http_status: 403 headers_observed: [x-security-bugs-report, x-security-bugs-rewards] fetched: '2026-08-06' - source: https://ajaib.co.id/.well-known/security.txt kind: security.txt (live probe) http_status: 404 result: absent gaps: - >- No /.well-known/security.txt. The same two facts Ajaib already serves in custom headers (security@ajaib.co.id, a rewards programme) would satisfy RFC 9116 Contact: and Policy: fields and be found by every standard scanner. - >- No public disclosure policy page, no scope statement, no safe-harbour language, and no named bug-bounty platform, so a reporter cannot tell what is in scope or what protection they have.