lemlist · Vulnerability Disclosure

Lemlist Vulnerability Disclosure

Vulnerability disclosure

lemlist runs a coordinated vulnerability disclosure program on Hackerone.

Email OutreachSales EngagementCold EmailSales AutomationLinkedIn OutreachLead GenerationData EnrichmentDeliverabilityCRMMultichannel MessagingWebhookMCP
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://hackerone.com/lemlist
policy:
- https://hackerone.com/lemlist
contact: []
program:
  platform: HackerOne
  handle: lemlist
  name: lemlist Vulnerability Disclosure Program
  type: vulnerability-disclosure
  state: public_mode
  bounty: unknown
evidence:
- source: https://hackerone.com/lemlist
  kind: bug-bounty-platform
  http_status: 200
  detail: 'page title "lemlist - Vulnerability Disclosure Program | HackerOne"'
- source: https://hackerone.com/graphql
  kind: platform-api
  http_status: 200
  detail: 'query team(handle:"lemlist") returned {"handle":"lemlist","name":"lemlist","state":"public_mode"}
    — the program exists and is public'
gaps:
- item: security.txt
  detail: >-
    No RFC 9116 /.well-known/security.txt on any lemlist host. www.lemlist.com and
    developer.lemlist.com return 404; api.lemlist.com and app.lemlist.com return a
    soft-200 HTML application shell. Publishing one that points at the HackerOne
    program would make this program machine-discoverable.
- item: on-site disclosure page
  detail: >-
    /security, /legal/security and /responsible-disclosure on www.lemlist.com all
    return 404 — the program is only discoverable on HackerOne.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lemlist-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.