Muck Rack · Vulnerability Disclosure

Muck Rack Vulnerability Disclosure

Vulnerability disclosure

Muck Rack runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Public RelationsMedia MonitoringMedia DatabaseJournalistsCommunicationsPress ReleasesEarned MediaSocial ListeningMarketingNewsAnalyticsCompany
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@muckrack.com

Source

Vulnerability Disclosure

muck-rack-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-26'
method: searched
source: https://muckrack.com/responsible-disclosure
docs: https://muckrack.com/responsible-disclosure
published: true
policy_url: https://muckrack.com/responsible-disclosure
contact: security@muckrack.com
contact_type: email
bug_bounty: false
rewards: false
rewards_note: >-
  "Muck Rack does not offer monetary compensation for reports at this time." No
  HackerOne, Bugcrowd or Intigriti program was found.
safe_harbor: true
safe_harbor_note: >-
  "Muck Rack will not engage in legal action against individuals who submit vulnerability
  reports through our Vulnerability Reporting inbox", conditional on the reporter adhering
  to the laws of their location and Muck Rack's, and refraining from public disclosure
  before a mutually agreed timeframe expires.
coordinated_disclosure: true
response_sla: null
response_sla_note: >-
  No response timeframe is committed. The policy says only that Muck Rack "will provide an
  update on the status of the vulnerability" if necessary or if requested by the reporter
  in writing.
out_of_scope:
- Denial of service / DDoS
- Spamming
- Social engineering and phishing
- Automated vulnerability scanning
- Attacks on physical property or data centers
security_txt:
  served: false
  path: /.well-known/security.txt
  status: 404
  note: >-
    THE DISCOVERABILITY GAP. A real, well-formed responsible disclosure policy with a
    dedicated security@ inbox and safe harbor exists — but it is not reachable at the
    RFC 9116 well-known location, so no automated scanner or agent can find it. Publishing
    a two-line security.txt pointing Contact: and Policy: at what already exists would
    close this at essentially zero cost.
also_referenced_from: https://muckrack.com/legal-and-security

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/muck-rack-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.