Brevo Vulnerability Disclosure
Brevo publishes a Responsible Disclosure Policy as a legal page, linked from the footer of every www.brevo.com page. It names a dedicated intake address, states the disclosure rules and the evidence a submission must carry. It is NOT exposed as an RFC 9116 security.txt — /.well-known/security.txt returns a Next.js 500 error page on www.brevo.com and 404 on api.brevo.com and developers.brevo.com — so a machine looking for the standard discovery path finds nothing. There is no public bug bounty program (no HackerOne, Bugcrowd or Intigriti listing found).
Brevo runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.