Brandwatch · Vulnerability Disclosure

Brandwatch Vulnerability Disclosure

Vulnerability disclosure

Brandwatch publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AnalyticsSocial-MediaSocial Media MonitoringConsumer IntelligenceBrand ManagementSentiment Analysis
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@brandwatch.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.brandwatch.com/legal/information-security/
policy:
  - https://www.brandwatch.com/legal/information-security/
policy_note: >-
  Section 11, "Vulnerability Disclosure", of the Brandwatch Security Programme
  page. It is a prose section of a broader security page, not a standalone
  disclosure policy URL and not an RFC 9116 security.txt.
contact:
  - security@brandwatch.com
contact_note: >-
  Published on the Information Security page behind Cloudflare email
  obfuscation; decoded from the page's data-cfemail attribute on 2026-08-13.
  privacy@brandwatch.com is published alongside it for privacy and compliance
  matters.
bug_bounty:
  program: false
  platform: null
  statement: >-
    "We do not have an official bug bounty programme (nor do we expect to create
    one in the near future). This means we do not have standing financial or
    personnel resources dedicated to handling unsolicited bug reports."
  compensation: discretionary
  compensation_note: >-
    "we may choose to provide compensation for these submissions where
    appropriate ... our assessment of what's appropriate may differ from yours,
    and we unfortunately cannot negotiate reward amounts."
accepts_reports: true
coordinated_disclosure:
  requested: true
  statement: >-
    "Vulnerabilities found are not confidential, but we would ask that you not
    publicly disclose the things you find without giving us time to remedy any
    issues."
  embargo_period: unspecified
  safe_harbor: not stated
security_testing:
  vulnerability_testing: at least monthly
  penetration_testing: third-party, intensive manual and automated
  source: https://www.brandwatch.com/legal/information-security/
security_txt:
  served: false
  probed:
    - url: https://www.brandwatch.com/.well-known/security.txt
      status: 404
    - url: https://developers.brandwatch.com/.well-known/security.txt
      status: 404
    - url: https://api.brandwatch.com/.well-known/security.txt
      status: 401
  note: >-
    Brandwatch has both a disclosure policy and a security@ contact but does not
    publish them at the machine-readable RFC 9116 location, so an automated
    scanner finds nothing. This is a one-file fix for the provider.
evidence:
  - source: https://www.brandwatch.com/legal/information-security/
    status: 200
    kind: disclosure-policy-section
    keywords:
      - vulnerability disclosure
      - bug bounty
      - security@brandwatch.com
      - responsible disclosure
  - source: https://www.brandwatch.com/.well-known/security.txt
    status: 404
    kind: security.txt-absent