Agorapulse · Vulnerability Disclosure

Agorapulse Vulnerability Disclosure

Vulnerability disclosure

Agorapulse runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Social Media ManagementSocial-MediaCRMAnalyticsPublishingInbox ManagementSocial Listening
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security-trust@agorapulse.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.agorapulse.com/security/
policy:
- https://www.agorapulse.com/security/
program:
  type: bug bounty
  platform: HackerOne
  visibility: private
  invite_process: >-
    The program is private, so there is no public HackerOne URL. Researchers email
    security-trust@agorapulse.com with their HackerOne username, a description of the vulnerability
    and the affected subdomain, and are invited in.
contact:
- security-trust@agorapulse.com
security_txt:
  published: false
  note: >-
    No RFC 9116 security.txt is served on any Agorapulse-controlled host. The 200 at
    support.agorapulse.com/.well-known/security.txt is Intercom's document — it names Bugcrowd and
    security@intercom.com and its Canonical field points at app.intercom.com. Not credited here.
evidence:
- source: https://www.agorapulse.com/security/
  kind: disclosure page
  quote: 'Potential vulnerabilities can be reported through our private bug bounty program running on HackerOne'
  keywords: [vulnerability, bug bounty, hackerone, responsible disclosure]
x-evidence:
- {fetched: '2026-08-13', url: 'https://www.agorapulse.com/security/', http_status: 200}
- {fetched: '2026-08-13', url: 'https://support.agorapulse.com/.well-known/security.txt', http_status: 200, note: Intercom document, rejected}
- {fetched: '2026-08-13', url: 'https://www.agorapulse.com/.well-known/security.txt', http_status: 404}