Legal

Security

Reporting a vulnerability

We take the security of ApkSee, our website and our license servers seriously. If you have found a vulnerability, please write to [email protected] with the subject “Security”. Describe the problem, the affected version or address and the steps to reproduce it. A machine-readable contact entry is available at /.well-known/security.txt.

What you can expect from us

  • Acknowledgement of receipt within 3 business days.
  • An initial assessment within 10 business days.
  • Information about the fix and, if you wish, credit in the release notes.
  • No legal action against you if you act in good faith and within this policy.
  • We do not currently run a bug bounty programme and pay no rewards; we thank you by naming you in the release notes.

Rules

  • Do not access other customers’ data, do not change or delete any data, and stop testing as soon as you gain access to data that is not yours.
  • No denial-of-service tests, no spam, no social engineering and no physical attacks.
  • Use only your own accounts and your own license keys for testing.
  • Give us a reasonable amount of time (usually 90 days) to fix the issue before you publish any details.

Out of scope

  • Reports from automated scanners without demonstrated impact.
  • Missing security headers without concrete exploitability, clickjacking on pages without sensitive actions, self-XSS.
  • Vulnerabilities in third-party apps that you have found with ApkSee; please report those to the respective vendor.

How we protect you

All connections are TLS-encrypted. Playbooks can be signed and verified before they run; licenses are cryptographically signed and bound to devices. We store passwords only as an Argon2id hash; two-factor sign-in via TOTP is available optionally. Payment data is processed exclusively by Stripe. The analysis of your apps runs locally and never leaves your computer.