Lithium · Vulnerability Disclosure

Lithium Vulnerability Disclosure

Vulnerability disclosure

Khoros publishes a security-program page describing vulnerability management, secure development and penetration testing, but it does not publish a coordinated vulnerability disclosure channel. There is no security.txt on any host, no security@ address, no responsible-disclosure page and no verifiable public bug-bounty program. A researcher with a finding has no documented route in other than the general support and compliance contacts.

Lithium runs a coordinated vulnerability disclosure program on Hackerone.

CompanyMarTechCommunitySocial-MediaCustomer EngagementCustomer-SupportChatbotsMessagingAnalyticsMarketing
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: >-
  https://khoros.ai/khoros-security/, https://khoros.ai/trust-center/, and live probes for
  /.well-known/security.txt, /responsible-disclosure, /vulnerability-disclosure and the
  HackerOne and Bugcrowd program slugs.
description: >-
  Khoros publishes a security-program page describing vulnerability management, secure
  development and penetration testing, but it does not publish a coordinated vulnerability
  disclosure channel. There is no security.txt on any host, no security@ address, no
  responsible-disclosure page and no verifiable public bug-bounty program. A researcher with
  a finding has no documented route in other than the general support and compliance
  contacts.

security_policy:
  url: https://khoros.ai/khoros-security/
  published: true
  covers:
    - Security operations (monitoring, encryption at rest and in transit, vulnerability management, intrusion detection, data retention and destruction)
    - Secure application development (secure SDLC, code review, security testing, regular penetration testing)
    - Physical security
    - Incident response
    - Business continuity and disaster recovery
    - Vendor management
    - Certifications

disclosure_channel:
  published: false
  security_txt: false
  security_email: null
  disclosure_page: null

bug_bounty:
  published: false
  hackerone: unverified
  bugcrowd: false
  note: >-
    hackerone.com/khoros returns HTTP 200, but the response is HackerOne's generic
    single-page-app shell with no program content, so it is not evidence of a public
    program. bugcrowd.com/khoros is a 404. No bounty program is claimed on any Khoros page.

contacts:
  addresses:
    - {email: compliance@khoros.com, purpose: Compliance and customer security documentation}
    - {email: privacy@khoros.com, purpose: Privacy and data protection}
    - {email: legal@khoros.com, purpose: Legal}
    - {email: info@khoros.com, purpose: General}
  note: >-
    These are the addresses published on the Trust Center. None is designated for security
    vulnerability reports.

evidence:
  - {source: 'https://khoros.ai/khoros-security/', kind: security-policy-page, status: 200}
  - {source: 'https://khoros.ai/trust-center/', kind: trust-center, status: 200}
  - {source: '/.well-known/security.txt', kind: probe, status: 404, hosts: [khoros.ai, www.khoros.com]}
  - {source: 'https://khoros.ai/responsible-disclosure', kind: probe, status: 404}
  - {source: 'https://khoros.ai/vulnerability-disclosure', kind: probe, status: 404}
  - {source: 'https://bugcrowd.com/khoros', kind: probe, status: 404}

gaps:
  - No RFC 9116 security.txt on any host in the estate.
  - No security@ mailbox or dedicated disclosure form.
  - No published safe-harbour statement or disclosure timeline.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lithium-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.