MNTN · Vulnerability Disclosure

Mntn Vulnerability Disclosure

Vulnerability disclosure

MNTN runs a coordinated vulnerability disclosure program on Hackerone.

Connected TVctv-advertisingAdvertisingPerformance MarketingStreaming TVMedia BuyingAttributionAudience TargetingConversion TrackingProgrammatic Advertisingprivate-marketplacemarketing-reportingAdTech
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-12'
method: searched
source: https://mountain.com/security/
program:
  published: true
  type: security-contact
  page: https://mountain.com/security/
  contact:
    email: security@mountain.com
    statement: "If you think you've discovered a vulnerability, please email security@mountain.com"
  bug_bounty:
    exists: false
    platforms_checked: [HackerOne, Bugcrowd, Intigriti, YesWeHack]
    result: no program found
  safe_harbor:
    published: false
  scope:
    published: false
  response_targets:
    published: false
  pgp_key: null
security_txt:
  served: false
  probes:
  - {url: 'https://mountain.com/.well-known/security.txt', status: 404}
  - {url: 'https://www.mountain.com/.well-known/security.txt', status: 404}
  - {url: 'https://api.mountain.com/.well-known/security.txt', status: 401}
  - {url: 'https://api3.mountain.com/.well-known/security.txt', status: 404}
  - {url: 'https://help.mountain.com/.well-known/security.txt', status: 200, third_party: Intercom, note: "Intercom's own file on the vendor-hosted help subdomain, not MNTN's"}
  note: >-
    MNTN publishes a working disclosure contact on a human-readable page but serves no RFC 9116
    security.txt on any host it controls. The single 200 is the Intercom help-desk vendor's file and
    does not name MNTN. No type: SecurityTxt pointer is wired.
practices_claimed:
  source: https://mountain.com/security/
  items:
  - Data encryption at rest and in transit
  - Annual third-party audits
  - Annual penetration testing
  - Regular access control reviews
  - Intrusion detection system (IDS)
  - 24/7 on-call team rotation
  - Cybersecurity insurance
  - Subprocessor list available
note: >-
  A named, monitored security contact on a first-party page is a genuine disclosure surface, so a
  type: Security pointer is wired in apis.yml. What is missing is everything that makes the program
  machine-actionable: no security.txt, no published scope, no safe-harbor statement, and no stated
  response target.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mntn-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.