Frontify · Vulnerability Disclosure

Frontify Vulnerability Disclosure

Vulnerability disclosure

Frontify runs a named vulnerability-disclosure program with two intake paths — an official BugCrowd bug bounty and a direct security mailbox. The page states it in Frontify's own words: "The Frontify Bug Bounty — Report security issues through our official BugCrowd bounty program or contact our security team at security@frontify.com." The page's "Report vulnerability" button targets mailto:security@frontify.com.

Frontify runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

CompanyMarketingBrand ManagementDigital Asset ManagementDAMContentGraphQLCreative Operations
Program: Bugcrowd

Disclosure Policy

Policy

Security Contact

Contact
security@frontify.com

Source

Vulnerability Disclosure

frontify-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.frontify.com/en/security/
url: https://www.frontify.com/en/security/
description: >-
  Frontify runs a named vulnerability-disclosure program with two intake paths — an
  official BugCrowd bug bounty and a direct security mailbox. The page states it in
  Frontify's own words: "The Frontify Bug Bounty — Report security issues through our
  official BugCrowd bounty program or contact our security team at
  security@frontify.com." The page's "Report vulnerability" button targets
  mailto:security@frontify.com.
policy:
  - https://www.frontify.com/en/security/
contact:
  - security@frontify.com
bug_bounty:
  platform: BugCrowd
  program_url: null
  program_url_note: >-
    Frontify names BugCrowd as its official bounty platform but does not link a public
    program page from the security page, and no public BugCrowd program page for
    Frontify was found (bugcrowd.com/frontify and bugcrowd.com/engagements/frontify both
    returned 404). The program is therefore either private/invite-only or listed under a
    different handle. Recorded as named-but-unlinked rather than asserted as public.
security_txt:
  served: false
  note: >-
    No /.well-known/security.txt on any Frontify host — www.frontify.com 404s with an
    "Invalid .well-known request" stub. Publishing an RFC 9116 security.txt pointing at
    this page and mailbox is a one-file fix. See well-known/frontify-well-known.yml.
related_practices:
  source: https://www.frontify.com/en/security/
  claims:
    - Development process follows OWASP guidelines with code reviews, pair programming and automated security tests.
    - Incident management and reporting process spanning internal operations and customer-facing services.
    - Customer notification within 48 hours of a security breach affecting customer data.
    - Nightly backups of files, databases, configuration and servers; disaster-recovery procedures tested at least annually.
evidence:
  - source: https://www.frontify.com/en/security/
    http_status: 200
    kind: security-page
    matched: [BugCrowd, "security@frontify.com", bug bounty]
    checked: '2026-08-13'
  - source: https://bugcrowd.com/frontify
    http_status: 404
    kind: bounty-program-lookup
    checked: '2026-08-13'
  - source: https://trust.frontify.com/
    http_status: 200
    kind: trust-center
    matched: [responsible disclosure]
    checked: '2026-08-13'
note: >-
  The mechanical probe (0-working/probe-security-programs.py) reported vdp=none for this
  provider because Frontify's disclosure surface is at /en/security/ rather than any of
  the conventional /security, /responsible-disclosure or /.well-known/security.txt paths
  the probe checks. This file is the searched upgrade over that miss.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/frontify-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.