Cordial · Vulnerability Disclosure

Cordial Vulnerability Disclosure

Vulnerability disclosure

Cordial runs a coordinated vulnerability disclosure program on Hackerone.

CompanyMarketingMarketing AutomationMessagingEmailSMSPush NotificationsCustomer Data PlatformPersonalizationCustomer EngagementArtificial IntelligenceRetailE-Commerce
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: probed
probe: true
result: none
found: false

note: >-
  No vulnerability disclosure surface was found for Cordial. This is a recorded negative result, not an
  unchecked box — every path below was fetched on 2026-08-04. Because there is no verified disclosure
  program, NO `Security` pointer is emitted in apis.yml; recording one would credit a posture Cordial
  does not publish.

policy: []
contact: []
bug_bounty: null

probes:
- {url: 'https://cordial.com/.well-known/security.txt', http_status: 404}
- {url: 'https://developers.cordial.com/.well-known/security.txt', http_status: 404}
- {url: 'https://api.cordial.io/.well-known/security.txt', http_status: 401, note: 'Blanket auth on the API host; not a published security.txt.'}
- {url: 'https://legal.cordial.com/.well-known/security.txt', http_status: 404}
- {url: 'https://mcp.cordial.io/.well-known/security.txt', http_status: 404}
- {url: 'https://cordial.com/responsible-disclosure/', http_status: 404}
- {url: 'https://cordial.com/security/responsible-disclosure/', http_status: 404}
- {url: 'https://cordial.com/vulnerability-disclosure/', http_status: 404}
- {url: 'https://cordial.com/security/', http_status: 200, note: 'Compliance page only — names SOC 2, GDPR, CCPA, Privacy Shield. Contains no disclosure policy, no security contact address, and no reporting instructions.'}
- {url: 'https://hackerone.com/cordial', http_status: 200, note: 'FALSE POSITIVE — this handle belongs to an individual researcher account (username "cordial", display name "Abdullah", created 2022-04-28), not a Cordial program. Rejected.'}
- {url: 'https://bugcrowd.com/cordial', http_status: 301, note: 'Redirect, no program.'}

gap: >-
  Cordial holds SOC 2 Type II and processes contact PII at scale for enterprise consumer brands, yet
  publishes no RFC 9116 security.txt, no disclosure policy, no security contact address, and runs no
  coordinated disclosure or bug bounty program. A researcher who finds a flaw has no published route to
  report it. A security.txt on cordial.com is the single cheapest fix available to them.