generated: '2026-08-06' method: searched probe: true source: https://www.aptible.com/legal/responsible-disclosure-policy policy: - https://www.aptible.com/legal/responsible-disclosure-policy - https://www.aptible.com/legal/security-policy contact: - research@aptible.com security_txt: false bug_bounty: false safe_harbor: true policy_version: 3.7 - May 2026 in_scope_hosts: - api.aptible.com - app.aptible.com - auth.aptible.com - beta.aptible.com - billing.aptible.com - git.aptible.com - metrictunnel.aptible.com - slot-machine.aptible.com penetration_testing: dedicated_stacks: >- Customers may pen-test their own dedicated Stacks; the underlying infrastructure falls under AWS's Permitted Services. AWS "Other Simulated Events" require pre-approval from Aptible. shared_stacks: >- Application-level testing of the customer's own apps only, and only with prior written authorization from Aptible. source: https://www.aptible.com/legal/security-policy notes: >- Aptible runs a published responsible-disclosure program with an explicit safe harbour and a named in-scope host list, but it is NOT a paid bug bounty and it is NOT advertised at /.well-known/security.txt (that path 404s on every Aptible host). As of policy version 3.7 Aptible states a strict no-response posture toward AI-generated and otherwise non-compliant submissions. evidence: - source: https://www.aptible.com/legal/responsible-disclosure-policy http_status: 200 kind: disclosure-policy keywords: [responsible disclosure, safe harbor, research@aptible.com, scope] - source: https://www.aptible.com/legal/security-policy http_status: 200 kind: security-policy keywords: [security policy, penetration testing authorization] - source: https://www.aptible.com/.well-known/security.txt http_status: 404 kind: security.txt keywords: []