Datorama · Vulnerability Disclosure

Datorama Vulnerability Disclosure

Vulnerability disclosure

Datorama runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyAnalyticsMarketingMarketing IntelligenceAdvertisingDataBusiness IntelligenceReportingSalesforceMarketing AnalyticsData HarmonizationDashboardsMCP
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://security.salesforce.com/contact-us/

Source

Vulnerability Disclosure

datorama-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-12'
method: searched
probe: true
source: https://security.salesforce.com/responsible-disclosure-policy/
ownership_note: >-
  Salesforce acquired Datorama in August 2018 and operates it as Marketing Cloud Intelligence, so
  the vulnerability-disclosure programme covering the Datorama platform is Salesforce's — the same
  compliance site publishes a "Vulnerability/Penetration Report Summary - MC Intelligence (fka
  Datorama)" document under the Marketing Cloud - Intelligence service, which ties the programme to
  this product by name.
policy:
- https://security.salesforce.com/responsible-disclosure-policy/
contact:
- https://security.salesforce.com/contact-us/
security_txt: false
security_txt_note: >-
  No /.well-known/security.txt is served on datorama.com, www.datorama.com, api.datorama.com,
  platform.datorama.com or developers.datorama.com — nor on www.salesforce.com (404). See
  well-known/datorama-well-known.yml.
bug_bounty:
  public_program: false
  platform: null
  note: >-
    No HackerOne / Bugcrowd / Intigriti programme is linked from the policy page. Submission is via
    the "Security Vulnerability Finding Submittal Guide" process rather than a bounty platform.
safe_harbor:
  present: true
  statement_verbatim: >-
    "Salesforce pledges not to initiate legal action against researchers for penetrating or
    attempting to penetrate our systems as long as they adhere to this policy."
policy_highlights:
- verbatim: >-
    "Independent security researchers play a valuable role in internet security. As a result, we
    encourage responsible reporting of any vulnerabilities that may be found in our site or
    applications."
- verbatim: >-
    "As a component of responsible disclosure, Salesforce will notify potentially impacted customers
    when they must take action to patch or otherwise remediate a vulnerability in advance of
    publicly disclosing the issue and releasing a Common Vulnerabilities and Exposures (CVE)."
- verbatim: >-
    "Whenever a Trial or Developer Edition is available, please conduct all vulnerability testing
    against such instances. Always use test or demo accounts when testing our online services."
- verbatim: >-
    "Privately share full details of the suspected vulnerability with the Salesforce Security team
    by following the Security Vulnerability Finding Submittal Guide process."
prohibited_research:
- Actions that may negatively affect Salesforce or its users (spam, brute force, denial of service)
- Accessing or attempting to access data that does not belong to the researcher
recognition:
  contributors_page: https://security.salesforce.com/security-research-contributors/
  note: Salesforce publishes a list of security research contributors.
evidence:
- {source: 'https://security.salesforce.com/responsible-disclosure-policy/', http_status: 200, kind: disclosure-policy, fetched: '2026-08-12'}
- {source: 'https://security.salesforce.com/', http_status: 200, kind: security-program-hub, fetched: '2026-08-12'}
- {source: 'https://compliance.salesforce.com/en/services/marketing-cloud-intelligence', http_status: 200, kind: pen-test-summary-listing, fetched: '2026-08-12', note: 'lists "Vulnerability/Penetration Report Summary - MC Intelligence (fka Datorama)"'}
- {source: 'https://www.salesforce.com/.well-known/security.txt', http_status: 404, kind: security.txt, fetched: '2026-08-12'}
probe_result:
  script: 0-working/probe-security-programs.py
  run: '2026-08-12'
  result: 'vdp=none'
  note: >-
    The mechanical probe found nothing because datorama.com 301s to a salesforce.com marketing page
    and every path on the datorama hosts returns a catch-all shell. This file is the searched
    upgrade over that null result.