Atolls · Vulnerability Disclosure

Atolls Vulnerability Disclosure

Vulnerability disclosure

Atolls runs a coordinated vulnerability disclosure program on Intigriti. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyConsumerE-CommerceAffiliate MarketingCashbackCouponsShoppingRetailIdentityOpenID Connect
Program: Intigriti security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@atolls.com

Source

Vulnerability Disclosure

atolls-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://atolls.com/.well-known/security.txt
policy:
- https://atolls.com/disclosure-policy
contact:
- mailto:security@atolls.com
bug_bounty:
  managed_by: Intigriti
  program: https://app.intigriti.com/programs/atolls/atollsvdp/detail
  model: >-
    One group-wide Atolls VDP on Intigriti. Two brands (mydealz.de and igraal.com)
    additionally run an INVITE-ONLY Intigriti program, requested by sending an
    Intigriti username and email to security@atolls.com.
preferred_languages: en
expires: '2027-04-29T23:59:59.000Z'
coverage:
  note: >-
    The same security address, disclosure policy and Intigriti program are published
    from five separate Atolls-owned hosts, which is unusually consistent for a
    multi-brand consumer group.
  hosts:
  - host: https://atolls.com
    security_txt: 200
    file: well-known/atolls-security.txt
    expires: '2027-04-29T23:59:59.000Z'
  - host: https://www.mydealz.de
    security_txt: 200
    file: well-known/atolls-mydealz-security.txt
    expires: '2027-06-29T21:59:00.000Z'
    program_scope: invite-only Intigriti program for this brand
  - host: https://www.hotukdeals.com
    security_txt: 200
    file: well-known/atolls-hotukdeals-security.txt
    expires: '2027-04-29T23:59:59.000Z'
  - host: https://www.igraal.com
    security_txt: 200
    file: well-known/atolls-igraal-security.txt
    expires: '2027-06-29T21:59:00.000Z'
    program_scope: invite-only Intigriti program for this brand
  - host: https://www.shoop.de
    security_txt: 200
    file: well-known/atolls-shoop-security.txt
    expires: '2027-06-29T21:59:00.000Z'
  - host: https://www.coupons.com
    security_txt: 404
  - host: https://www.pepper.com
    security_txt: soft-200
    note: HTML shell returned with a 200; no security.txt document is served.
evidence:
- source: https://atolls.com/.well-known/security.txt
  status: 200
  kind: RFC 9116 security.txt
- source: https://www.mydealz.de/.well-known/security.txt
  status: 200
  kind: RFC 9116 security.txt
- source: https://www.hotukdeals.com/.well-known/security.txt
  status: 200
  kind: RFC 9116 security.txt
- source: https://www.igraal.com/.well-known/security.txt
  status: 200
  kind: RFC 9116 security.txt
- source: https://www.shoop.de/.well-known/security.txt
  status: 200
  kind: RFC 9116 security.txt
- source: https://app.intigriti.com/programs/atolls/atollsvdp/detail
  kind: bug-bounty program (Intigriti), referenced from every security.txt above
- source: https://atolls.com/disclosure-policy
  status: 403
  kind: disclosure policy page — Cloudflare bot challenge on probe; URL taken verbatim
    from the security.txt Policy field, not asserted as read.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/atolls-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.