Datorama · Vulnerability Disclosure
Datorama Vulnerability Disclosure
Vulnerability disclosure
Datorama runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
CompanyAnalyticsMarketingMarketing IntelligenceAdvertisingDataBusiness IntelligenceReportingSalesforceMarketing AnalyticsData HarmonizationDashboardsMCP
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
https://security.salesforce.com/contact-us/
Source
Vulnerability Disclosure
generated: '2026-08-12'
method: searched
probe: true
source: https://security.salesforce.com/responsible-disclosure-policy/
ownership_note: >-
Salesforce acquired Datorama in August 2018 and operates it as Marketing Cloud Intelligence, so
the vulnerability-disclosure programme covering the Datorama platform is Salesforce's — the same
compliance site publishes a "Vulnerability/Penetration Report Summary - MC Intelligence (fka
Datorama)" document under the Marketing Cloud - Intelligence service, which ties the programme to
this product by name.
policy:
- https://security.salesforce.com/responsible-disclosure-policy/
contact:
- https://security.salesforce.com/contact-us/
security_txt: false
security_txt_note: >-
No /.well-known/security.txt is served on datorama.com, www.datorama.com, api.datorama.com,
platform.datorama.com or developers.datorama.com — nor on www.salesforce.com (404). See
well-known/datorama-well-known.yml.
bug_bounty:
public_program: false
platform: null
note: >-
No HackerOne / Bugcrowd / Intigriti programme is linked from the policy page. Submission is via
the "Security Vulnerability Finding Submittal Guide" process rather than a bounty platform.
safe_harbor:
present: true
statement_verbatim: >-
"Salesforce pledges not to initiate legal action against researchers for penetrating or
attempting to penetrate our systems as long as they adhere to this policy."
policy_highlights:
- verbatim: >-
"Independent security researchers play a valuable role in internet security. As a result, we
encourage responsible reporting of any vulnerabilities that may be found in our site or
applications."
- verbatim: >-
"As a component of responsible disclosure, Salesforce will notify potentially impacted customers
when they must take action to patch or otherwise remediate a vulnerability in advance of
publicly disclosing the issue and releasing a Common Vulnerabilities and Exposures (CVE)."
- verbatim: >-
"Whenever a Trial or Developer Edition is available, please conduct all vulnerability testing
against such instances. Always use test or demo accounts when testing our online services."
- verbatim: >-
"Privately share full details of the suspected vulnerability with the Salesforce Security team
by following the Security Vulnerability Finding Submittal Guide process."
prohibited_research:
- Actions that may negatively affect Salesforce or its users (spam, brute force, denial of service)
- Accessing or attempting to access data that does not belong to the researcher
recognition:
contributors_page: https://security.salesforce.com/security-research-contributors/
note: Salesforce publishes a list of security research contributors.
evidence:
- {source: 'https://security.salesforce.com/responsible-disclosure-policy/', http_status: 200, kind: disclosure-policy, fetched: '2026-08-12'}
- {source: 'https://security.salesforce.com/', http_status: 200, kind: security-program-hub, fetched: '2026-08-12'}
- {source: 'https://compliance.salesforce.com/en/services/marketing-cloud-intelligence', http_status: 200, kind: pen-test-summary-listing, fetched: '2026-08-12', note: 'lists "Vulnerability/Penetration Report Summary - MC Intelligence (fka Datorama)"'}
- {source: 'https://www.salesforce.com/.well-known/security.txt', http_status: 404, kind: security.txt, fetched: '2026-08-12'}
probe_result:
script: 0-working/probe-security-programs.py
run: '2026-08-12'
result: 'vdp=none'
note: >-
The mechanical probe found nothing because datorama.com 301s to a salesforce.com marketing page
and every path on the datorama hosts returns a catch-all shell. This file is the searched
upgrade over that null result.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/datorama-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.