NextRoll · Vulnerability Disclosure

Nextroll Vulnerability Disclosure

Vulnerability disclosure

NextRoll runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyAdvertisingAdTechMarketingAccount Based MarketingRetargetingAudiencesCampaign ManagementAnalyticsReportingMarTechAgents
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@nextroll.com

Source

Vulnerability Disclosure

nextroll-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-01'
method: searched
probe: true
source: https://security.nextroll.com/
policy:
- https://security.nextroll.com/
contact:
- security@nextroll.com
contact_form: 'mailto:security@nextroll.com?subject=SafeBase Responsible Disclosure
  Report for NextRoll'
program:
  type: coordinated disclosure
  control_published: Open to Responsible Disclosure
  location: App Security section of the NextRoll Trust Center (SafeBase)
  bug_bounty_platform: null
  bug_bounty_note: >-
    No public bug-bounty program page was found on hackerone.com, bugcrowd.com or
    intigriti.com for NextRoll or AdRoll. HackerOne appears on the trust center as the
    AUDITOR of NextRoll's penetration test report, not as a public bounty host — the
    two are recorded separately here so the distinction is not lost.
  penetration_testing:
    auditor: HackerOne
    artifact: Pentest Report (gated behind a trust-center access request)
security_txt:
  published: false
  paths_probed:
  - https://www.nextroll.com/.well-known/security.txt
  - https://www.adroll.com/.well-known/security.txt
  - https://services.adroll.com/.well-known/security.txt
  - https://apidocs.nextroll.com/.well-known/security.txt
  note: >-
    None returned RFC 9116 text. www.rollworks.com returns HTTP 200 for the path but
    the body is the HubSpot marketing homepage HTML — a catch-all, not a security.txt.
other_contacts:
  data_protection_officer: dpo@nextroll.com
  support: support@nextroll.com
  privacy_requests: https://nextroll-privacy.relyance.ai
evidence:
- source: https://security.nextroll.com/
  kind: trust-center
  http_status: 200
  keywords: [responsible disclosure, security@nextroll.com, pentest report, app security]
- source: https://www.nextroll.com/trust-center
  kind: trust-page
  http_status: 200
gaps:
- No RFC 9116 security.txt on any host, so an automated scanner finds no disclosure
  contact without reading a JavaScript-rendered trust portal.
- No published disclosure policy text, scope statement, or safe-harbour language —
  only a "we are open to responsible disclosure" control and an email address.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/nextroll-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.