Legal
Security
Reporting a vulnerability
We take the security of ApkSee, our website and our license servers seriously. If you have found a vulnerability, please write to [email protected] with the subject “Security”. Describe the problem, the affected version or address and the steps to reproduce it. A machine-readable contact entry is available at /.well-known/security.txt.
What you can expect from us
- Acknowledgement of receipt within 3 business days.
- An initial assessment within 10 business days.
- Information about the fix and, if you wish, credit in the release notes.
- No legal action against you if you act in good faith and within this policy.
- We do not currently run a bug bounty programme and pay no rewards; we thank you by naming you in the release notes.
Rules
- Do not access other customers’ data, do not change or delete any data, and stop testing as soon as you gain access to data that is not yours.
- No denial-of-service tests, no spam, no social engineering and no physical attacks.
- Use only your own accounts and your own license keys for testing.
- Give us a reasonable amount of time (usually 90 days) to fix the issue before you publish any details.
Out of scope
- Reports from automated scanners without demonstrated impact.
- Missing security headers without concrete exploitability, clickjacking on pages without sensitive actions, self-XSS.
- Vulnerabilities in third-party apps that you have found with ApkSee; please report those to the respective vendor.
How we protect you
All connections are TLS-encrypted. Playbooks can be signed and verified before they run; licenses are cryptographically signed and bound to devices. We store passwords only as an Argon2id hash; two-factor sign-in via TOTP is available optionally. Payment data is processed exclusively by Stripe. The analysis of your apps runs locally and never leaves your computer.