Contently · Vulnerability Disclosure

Contently Vulnerability Disclosure

Vulnerability disclosure

Contently runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyContent MarketingTalent MarketplaceFreelanceContent CreationPublishingEditorial WorkflowRegulated ContentCompliance
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@contently.com

Source

Vulnerability Disclosure

contently-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
source: https://contently.com/trust/security/
probe: true
security_txt: false
security_txt_note: >-
  /.well-known/security.txt returns 404 on contently.com, api.contently.com, developer.contently.com
  and mcp.contently.com. See well-known/contently-well-known.yml.
formal_vdp: false
bug_bounty: false
bug_bounty_platforms_checked:
- HackerOne
- Bugcrowd
- Intigriti
policy: []
contact:
- security@contently.com
response_sla: 4 business hours
reporting_channels:
- url: https://contently.com/trust/security/
  kind: named-security-contact
  detail: >-
    Trust center names security@contently.com as the owner and states "For incident reporting,
    regulator inquiries, or ad-hoc compliance asks. Response SLA: 4 business hours."
- url: https://support.contently.com
  kind: support-portal
  detail: Kayako-hosted support portal (contently-support.kayako.com), reachable and returning 200
evidence:
- source: https://contently.com/trust/security/
  http_status: 200
  kind: security-contact
  detail: 'Owner: security@contently.com; Response SLA: 4 business hours'
- source: https://contently.com/trust/security/
  http_status: 200
  kind: controls
  detail: >-
    Published controls matrix includes "Penetration testing — Annual + on-release" and
    "Incident response — 24/7 on-call"
- source: https://support.contently.com
  http_status: 200
  kind: support-portal
- source: https://contently.com/.well-known/security.txt
  http_status: 404
  kind: negative-probe
notes: >-
  Contently publishes a named, SLA-backed security contact and an incident-response control, which is a
  real disclosure channel. It does NOT publish a formal vulnerability-disclosure policy, a safe-harbour
  statement, a scope definition, or a bug bounty, and it serves no security.txt. The channel exists;
  the policy does not.
  CORRECTION — a prior round cited https://contently.com/security as the source. That URL 301-redirects
  to a legacy slug (/trust-image-2018/security/) which serves the same trust-center page; the canonical
  source is https://contently.com/trust/security/ and this file now cites it.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/contently-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.