Lithium · Vulnerability Disclosure

Lithium Vulnerability Disclosure

Vulnerability disclosure

Khoros publishes a security-program page describing vulnerability management, secure development and penetration testing, but it does not publish a coordinated vulnerability disclosure channel. There is no security.txt on any host, no security@ address, no responsible-disclosure page and no verifiable public bug-bounty program. A researcher with a finding has no documented route in other than the general support and compliance contacts.

Lithium runs a coordinated vulnerability disclosure program on Hackerone.

CompanyMartechCommunitySocial MediaCustomer EngagementCustomer SupportChatbotsMessagingAnalyticsMarketing
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: >-
  https://khoros.ai/khoros-security/, https://khoros.ai/trust-center/, and live probes for
  /.well-known/security.txt, /responsible-disclosure, /vulnerability-disclosure and the
  HackerOne and Bugcrowd program slugs.
description: >-
  Khoros publishes a security-program page describing vulnerability management, secure
  development and penetration testing, but it does not publish a coordinated vulnerability
  disclosure channel. There is no security.txt on any host, no security@ address, no
  responsible-disclosure page and no verifiable public bug-bounty program. A researcher with
  a finding has no documented route in other than the general support and compliance
  contacts.

security_policy:
  url: https://khoros.ai/khoros-security/
  published: true
  covers:
    - Security operations (monitoring, encryption at rest and in transit, vulnerability management, intrusion detection, data retention and destruction)
    - Secure application development (secure SDLC, code review, security testing, regular penetration testing)
    - Physical security
    - Incident response
    - Business continuity and disaster recovery
    - Vendor management
    - Certifications

disclosure_channel:
  published: false
  security_txt: false
  security_email: null
  disclosure_page: null

bug_bounty:
  published: false
  hackerone: unverified
  bugcrowd: false
  note: >-
    hackerone.com/khoros returns HTTP 200, but the response is HackerOne's generic
    single-page-app shell with no program content, so it is not evidence of a public
    program. bugcrowd.com/khoros is a 404. No bounty program is claimed on any Khoros page.

contacts:
  addresses:
    - {email: compliance@khoros.com, purpose: Compliance and customer security documentation}
    - {email: privacy@khoros.com, purpose: Privacy and data protection}
    - {email: legal@khoros.com, purpose: Legal}
    - {email: info@khoros.com, purpose: General}
  note: >-
    These are the addresses published on the Trust Center. None is designated for security
    vulnerability reports.

evidence:
  - {source: 'https://khoros.ai/khoros-security/', kind: security-policy-page, status: 200}
  - {source: 'https://khoros.ai/trust-center/', kind: trust-center, status: 200}
  - {source: '/.well-known/security.txt', kind: probe, status: 404, hosts: [khoros.ai, www.khoros.com]}
  - {source: 'https://khoros.ai/responsible-disclosure', kind: probe, status: 404}
  - {source: 'https://khoros.ai/vulnerability-disclosure', kind: probe, status: 404}
  - {source: 'https://bugcrowd.com/khoros', kind: probe, status: 404}

gaps:
  - No RFC 9116 security.txt on any host in the estate.
  - No security@ mailbox or dedicated disclosure form.
  - No published safe-harbour statement or disclosure timeline.