BidMachine · Vulnerability Disclosure

Bidmachine Io Vulnerability Disclosure

Vulnerability disclosure

BidMachine publishes a Responsible Vulnerability Disclosure Policy as a web page (linked from the site footer as "Report an IT Vulnerability"). Scope: "all BidMachine-owned systems, services, APIs, and applications operating under the bidmachine.io domain and any associated subdomains". Reports go to the security mailbox; the policy sets researcher rules (no exploitation, no disruption, no public disclosure before remediation) and commits to prompt, transparent response. No bug bounty platform (HackerOne/Bugcrowd/Intigriti) and no RFC 9116 security.txt on any host. The page lives on www.bidmachine.com; https://bidmachine.io/responsible-vulnerability-disclosure-policy 301s to it.

BidMachine runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AdvertisingAdTechMobile AdvertisingAd ExchangeAd MediationIn-App BiddingOpenRTBApp MonetizationProgrammatic AdvertisingMobile SDKReportingCompany
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@bidmachine.io

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-19'
method: searched
probe: true
source: https://www.bidmachine.com/responsible-vulnerability-disclosure-policy
description: >-
  BidMachine publishes a Responsible Vulnerability Disclosure Policy as a web page (linked from the
  site footer as "Report an IT Vulnerability"). Scope: "all BidMachine-owned systems, services, APIs,
  and applications operating under the bidmachine.io domain and any associated subdomains". Reports
  go to the security mailbox; the policy sets researcher rules (no exploitation, no disruption, no
  public disclosure before remediation) and commits to prompt, transparent response. No bug bounty
  platform (HackerOne/Bugcrowd/Intigriti) and no RFC 9116 security.txt on any host. The page lives
  on www.bidmachine.com; https://bidmachine.io/responsible-vulnerability-disclosure-policy 301s to it.
policy:
  - https://www.bidmachine.com/responsible-vulnerability-disclosure-policy
contact:
  - security@bidmachine.io
bug_bounty: false
safe_harbor: >-
  "Researchers following these guidelines will be considered acting in good faith" (policy section 4);
  the page does not use the phrase safe harbor.
scope: all BidMachine-owned systems, services, APIs and applications under the bidmachine.io domain and its subdomains; third-party partner platforms excluded
security_txt: false
evidence:
  - {source: https://www.bidmachine.com/responsible-vulnerability-disclosure-policy, kind: disclosure page, http_status: 200, keywords: [responsible vulnerability disclosure policy, security team, report submission, proof-of-concept, good faith]}
  - {source: https://bidmachine.io/responsible-vulnerability-disclosure-policy, kind: redirect, http_status: 301}
  - {source: https://www.bidmachine.io/.well-known/security.txt, kind: security.txt, http_status: 404}
  - {source: https://www.bidmachine.com/.well-known/security.txt, kind: security.txt, http_status: 404}
  - {source: https://api-eu.bidmachine.io/.well-known/security.txt, kind: security.txt, http_status: 404}
note: The contact address is Cloudflare-obfuscated in the page HTML (data-cfemail) and was decoded locally; it is security@bidmachine.io.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bidmachine-io-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.