Mention · Vulnerability Disclosure

Mention Vulnerability Disclosure

Vulnerability disclosure

Mention runs a coordinated vulnerability disclosure program on Hackerone.

AlertsBrand MonitoringMedia MonitoringSocial ListeningSocial-MediaSentiment AnalysisReputation ManagementInfluencer MarketingCompetitive IntelligenceStreamingMarketing
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: >-
  https://mention.com/en/terms-and-conditions/#security-policy, /.well-known/security.txt probes on
  mention.com and api.mention.com, and https://www.agorapulse.com/security/ (parent brand)
summary: >-
  Mention publishes a Security Policy but NO vulnerability disclosure program of its own: no
  security.txt, no security contact address, no bug bounty, no reporting instructions and no safe
  harbour statement. The nearest reachable program belongs to Agorapulse, Mention's parent brand,
  and it is a PRIVATE (invitation-only) HackerOne program that does not name Mention in scope.
mention_program:
  published: false
  security_txt: false
  policy_url: https://mention.com/en/terms-and-conditions/#security-policy
  policy_covers: >-
    Hosting, data residency, availability goal, application stack, access control, backups,
    deployment process, privacy governance, personnel and breach notification. It does not tell a
    researcher how to report a vulnerability.
  reporting_channel: none published
  security_contact: none published
  bug_bounty: none
  safe_harbour: false
  breach_notification:
    stated: true
    detail: >-
      "Mention has established a routine for managing personal data breaches with an escalation
      program ... report about an incident within 72 hours to the data authority in France (CNIL)."
      This is regulator notification, not researcher intake.
  generic_contacts:
    - info@mention.com
    - gdpr@mention.com
  note: >-
    Neither address is presented as a security channel; they are the general and privacy contacts.
parent_brand_program:
  company: Agorapulse
  relationship: >-
    Mention is sold by Agorapulse SAS (General Terms of Sale, version Apr 15, 2025) and mention.com
    routes its trial and demo funnels to social.agorapulse.com. This entry is recorded for context
    only — it is NOT credited to Mention, because Agorapulse's security page does not name Mention as
    a covered product and mention.com does not link to it.
  url: https://www.agorapulse.com/security/
  security_contact: security-trust@agorapulse.com
  bug_bounty:
    platform: HackerOne
    public: false
    quote: >-
      "Potential vulnerabilities can be reported through our private bug bounty program running on
      HackerOne."
  trust_center: https://www.agorapulse.com/trust-center/
  status_page: https://status.agorapulse.com/
evidence:
  - url: https://mention.com/.well-known/security.txt
    http_status: 404
    fetched: '2026-08-13'
  - url: https://api.mention.com/.well-known/security.txt
    http_status: 404
    fetched: '2026-08-13'
  - url: https://mention.com/en/terms-and-conditions/
    http_status: 200
    fetched: '2026-08-13'
    note: Contains a #security-policy section, version Apr 22, 2022.
recommendations:
  - Serve an RFC 9116 /.well-known/security.txt on mention.com and api.mention.com with Contact, Policy and Expires.
  - Publish a reporting address and a safe-harbour statement alongside the existing Security Policy.
  - State whether the Agorapulse HackerOne program covers Mention, so researchers know where to send findings.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mention-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.