Instapage · Vulnerability Disclosure

Instapage Vulnerability Disclosure

Vulnerability disclosure

Instapage runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Landing PagesConversion OptimizationMarketingA/B TestingPost-Click OptimizationLead Generation
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
hackerone@dochub.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://policies.airslate.com/bug-bounty-program
policy:
- https://policies.airslate.com/bug-bounty-program
contact:
- hackerone@dochub.com
program:
  name: airSlate Bug Bounty Program
  operator: airSlate (Instapage's parent company)
  platform: HackerOne
  intake: >-
    Reports are accepted only through the airSlate HackerOne portal, or by email to
    hackerone@dochub.com which auto-generates a HackerOne report.
  rewards: monetary, subject to published eligibility requirements
  covers_instapage: true
  scope_evidence: >-
    The programme's out-of-scope list explicitly names Instapage — "Any vulnerabilities that arise
    solely from user-created pages on Instapage, such as reflected/stored XSS, open redirects,
    clickjacking, phishing, or spoofing" — which establishes that Instapage itself is in scope and
    only customer-authored page content is carved out.
  linked_from: https://instapage.com/security (site footer, "Bug Bounty Program")
security_txt:
  served: false
  note: >-
    No /.well-known/security.txt on instapage.com, api.instapage.com, devdocs.instapage.com or
    app.instapage.com — see well-known/instapage-well-known.yml. The disclosure route is published on
    the parent company's policy site instead, which is why the mechanical probe found nothing.
security_program:
  url: https://instapage.com/security
  vulnerability_management: >-
    Instapage publishes a Vulnerability Management Program (identify, prioritize, manage and report
    threats using a risk-based approach) and an Information Security Incident Management Program.
  testing_cadence: >-
    Monthly network scans, quarterly vulnerability assessments, internal and external penetration
    tests once a year.
  frameworks: ISO 27001/2 and NIST 800-53 aligned policies, reviewed yearly or after significant
    changes.
evidence:
- source: https://policies.airslate.com/bug-bounty-program
  http_status: 200
  kind: bug-bounty-policy
  keywords: [bug bounty, hackerone, responsible, in scope, out of scope, instapage]
- source: https://instapage.com/security
  http_status: 200
  kind: security-program-page
  keywords: [vulnerability management program, penetration test, incident management]
x-evidence:
  fetched: '2026-08-13'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/instapage-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.