generated: '2026-07-31' method: probed probe: true found: false source: live probes probed: - url: https://www.appsflyer.com/.well-known/security.txt http_status: 403 - url: https://dev.appsflyer.com/.well-known/security.txt http_status: 200 note: HTML docs shell, not RFC 9116 - url: https://hq1.appsflyer.com/.well-known/security.txt http_status: 202 note: empty catch-all - url: https://support.appsflyer.com/.well-known/security.txt http_status: 404 - url: https://www.appsflyer.com/responsible-disclosure/ http_status: 404 - url: https://www.appsflyer.com/legal/vulnerability-disclosure/ http_status: 404 - url: https://hackerone.com/appsflyer http_status: 404 - url: https://bugcrowd.com/appsflyer http_status: 404 - url: https://www.appsflyer.com/security/ http_status: 200 note: security posture marketing page — no disclosure instructions, no security@ contact, no bug bounty policy: [] contact: [] note: AppsFlyer publishes no RFC 9116 security.txt, no responsible-disclosure page, and no public bug-bounty program that could be verified. This is a recorded absence, not a gap in the probe. No Security pointer is wired into apis.yml as a result.