Mention · Vulnerability Disclosure
Mention Vulnerability Disclosure
Vulnerability disclosure
Mention runs a coordinated vulnerability disclosure program on Hackerone.
AlertsBrand MonitoringMedia MonitoringSocial ListeningSocial-MediaSentiment AnalysisReputation ManagementInfluencer MarketingCompetitive IntelligenceStreamingMarketing
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-13'
method: searched
source: >-
https://mention.com/en/terms-and-conditions/#security-policy, /.well-known/security.txt probes on
mention.com and api.mention.com, and https://www.agorapulse.com/security/ (parent brand)
summary: >-
Mention publishes a Security Policy but NO vulnerability disclosure program of its own: no
security.txt, no security contact address, no bug bounty, no reporting instructions and no safe
harbour statement. The nearest reachable program belongs to Agorapulse, Mention's parent brand,
and it is a PRIVATE (invitation-only) HackerOne program that does not name Mention in scope.
mention_program:
published: false
security_txt: false
policy_url: https://mention.com/en/terms-and-conditions/#security-policy
policy_covers: >-
Hosting, data residency, availability goal, application stack, access control, backups,
deployment process, privacy governance, personnel and breach notification. It does not tell a
researcher how to report a vulnerability.
reporting_channel: none published
security_contact: none published
bug_bounty: none
safe_harbour: false
breach_notification:
stated: true
detail: >-
"Mention has established a routine for managing personal data breaches with an escalation
program ... report about an incident within 72 hours to the data authority in France (CNIL)."
This is regulator notification, not researcher intake.
generic_contacts:
- info@mention.com
- gdpr@mention.com
note: >-
Neither address is presented as a security channel; they are the general and privacy contacts.
parent_brand_program:
company: Agorapulse
relationship: >-
Mention is sold by Agorapulse SAS (General Terms of Sale, version Apr 15, 2025) and mention.com
routes its trial and demo funnels to social.agorapulse.com. This entry is recorded for context
only — it is NOT credited to Mention, because Agorapulse's security page does not name Mention as
a covered product and mention.com does not link to it.
url: https://www.agorapulse.com/security/
security_contact: security-trust@agorapulse.com
bug_bounty:
platform: HackerOne
public: false
quote: >-
"Potential vulnerabilities can be reported through our private bug bounty program running on
HackerOne."
trust_center: https://www.agorapulse.com/trust-center/
status_page: https://status.agorapulse.com/
evidence:
- url: https://mention.com/.well-known/security.txt
http_status: 404
fetched: '2026-08-13'
- url: https://api.mention.com/.well-known/security.txt
http_status: 404
fetched: '2026-08-13'
- url: https://mention.com/en/terms-and-conditions/
http_status: 200
fetched: '2026-08-13'
note: Contains a #security-policy section, version Apr 22, 2022.
recommendations:
- Serve an RFC 9116 /.well-known/security.txt on mention.com and api.mention.com with Contact, Policy and Expires.
- Publish a reporting address and a safe-harbour statement alongside the existing Security Policy.
- State whether the Agorapulse HackerOne program covers Mention, so researchers know where to send findings.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mention-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.