Movable Ink · Vulnerability Disclosure

Movable Ink Vulnerability Disclosure

Vulnerability disclosure

Movable Ink publishes a dedicated security-reporting email address on its own domain, but no vulnerability disclosure POLICY, no safe-harbour language, no scope statement, no response-time commitment, no bug bounty, and no RFC 9116 security.txt. Reporting a vulnerability to Movable Ink means emailing an address found on a marketing page — the channel exists, the program does not.

Movable Ink publishes a vulnerability disclosure policy for reporting security issues.

CompanyMarketingPersonalizationEmailCustomer DataMobile SDKArtificial IntelligenceAdvertising TechnologyContentEvents
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

movable-ink-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-04'
method: searched
source: https://movableink.com/privacy-security-and-compliance
name: Movable Ink Security Reporting
description: >-
  Movable Ink publishes a dedicated security-reporting email address on its own
  domain, but no vulnerability disclosure POLICY, no safe-harbour language, no
  scope statement, no response-time commitment, no bug bounty, and no RFC 9116
  security.txt. Reporting a vulnerability to Movable Ink means emailing an
  address found on a marketing page — the channel exists, the program does not.
program:
  published: false
  kind: contact-only
  bug_bounty: none
  platform: none
  safe_harbor: not published
  scope_statement: not published
  response_sla: not published
contacts:
- purpose: Report a security concern or vulnerability
  email: security@movableink.com
  source: https://movableink.com/privacy-security-and-compliance
  evidence: >-
    schema.org ContactPoint with contactType "Security Concerns" embedded in the
    page markup.
- purpose: Security and compliance inquiries
  email: infosec@movableink.com
  source: https://movableink.com/privacy-security-and-compliance
- purpose: Client trust / security review due diligence
  email: infosec-dd@movableink.com
  source: https://movableink.com/privacy-security-and-compliance
related_practices:
  source: https://movableink.com/privacy-security-and-compliance
  statements:
  - >-
    "Movable Ink engages a qualified independent security firm to perform
    comprehensive application and network penetration testing on an annual
    basis."
  - >-
    "Validated security advisories and vulnerability disclosures are reviewed and
    considered as part of Movable Ink's ongoing risk management processes."
  - Named program areas include Vulnerability & Patch Management, Threat
    Management, Intrusion Prevention & Detection, and Incident Management.
security_txt:
  published: false
  probes:
  - url: https://movableink.com/.well-known/security.txt
    status: 404
  - url: https://auth.movableink.com/.well-known/security.txt
    status: 404
  - url: https://collector.movableink-dmz.com/.well-known/security.txt
    status: 404
trust_center_field:
  report_vulnerability_url: ''
  note: >-
    Movable Ink's Conveyor Trust Center record carries an empty
    report_vulnerability_url — the platform has the field and it is unset.
gap_for_provider: >-
  Publish /.well-known/security.txt on movableink.com pointing at a disclosure
  policy page, and set report_vulnerability_url in the Trust Center. Both are
  low-effort and make an existing internal practice machine-discoverable.
x-evidence:
  fetched: '2026-08-04'
  probes:
  - url: https://movableink.com/privacy-security-and-compliance
    status: 200
  - url: https://movableink.com/.well-known/security.txt
    status: 404
  - url: https://trust.movableink.com/
    status: 200