Loomly · Vulnerability Disclosure

Loomly Vulnerability Disclosure

Vulnerability disclosure

Loomly publishes a named, linkable vulnerability reporting policy on its own marketing domain. Researchers email a security address to request a disclosure form. There is no bug bounty, no reward program, no published safe-harbor clause, and no stated response SLA.

Loomly runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Social-MediaContent CalendarSchedulingApproval WorkflowsAnalyticsBrand ManagementPublishingCommunity ManagementMarketingSocial Media Management
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emailsecurity@loomly.com
Contact
methodEmail security@loomly.com to request a vulnerability disclosure form; the report is submitted on that form.

Source

Vulnerability Disclosure

loomly-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.loomly.com/vulnerability_reporting_policy
name: Loomly Vulnerability Reporting Policy
description: >-
  Loomly publishes a named, linkable vulnerability reporting policy on its own
  marketing domain. Researchers email a security address to request a disclosure
  form. There is no bug bounty, no reward program, no published safe-harbor
  clause, and no stated response SLA.
policy_url: https://www.loomly.com/vulnerability_reporting_policy
contact:
  email: security@loomly.com
  method: >-
    Email security@loomly.com to request a vulnerability disclosure form; the
    report is submitted on that form.
scope:
  stated: >-
    Potential vulnerabilities on the Loomly platform, APIs, apps and services.
  quote: >-
    Loomly is "committed to working with security researchers to verify and
    address any potential vulnerabilities."
bug_bounty:
  present: false
  platform: null
  rewards: false
  note: >-
    No HackerOne, Bugcrowd, Intigriti or self-hosted bounty program was found for
    loomly.com.
safe_harbor:
  published: false
response_sla:
  published: false
security_txt:
  present: false
  probed:
    - url: https://www.loomly.com/.well-known/security.txt
      http_status: 404
    - url: https://app.loomly.com/.well-known/security.txt
      http_status: 404
    - url: https://status.loomly.com/.well-known/security.txt
      http_status: 404
  note: >-
    RFC 9116 security.txt is not served on any Loomly host, so the policy is
    discoverable only by a human reading the marketing site or the security page.
evidence:
  - url: https://www.loomly.com/vulnerability_reporting_policy
    http_status: 200
    fetched: '2026-08-13'
  - url: https://www.loomly.com/security
    http_status: 200
    fetched: '2026-08-13'
    note: Security page links the reporting policy and names security@loomly.com.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/loomly-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.