NextRoll · Vulnerability Disclosure

Nextroll Vulnerability Disclosure

Vulnerability disclosure

NextRoll runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyAdvertisingAdTechMarketingAccount Based MarketingRetargetingAudiencesCampaign ManagementAnalyticsReportingMarTechAgents
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@nextroll.com

Source

Vulnerability Disclosure

nextroll-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-01'
method: searched
probe: true
source: https://security.nextroll.com/
policy:
- https://security.nextroll.com/
contact:
- security@nextroll.com
contact_form: 'mailto:security@nextroll.com?subject=SafeBase Responsible Disclosure
  Report for NextRoll'
program:
  type: coordinated disclosure
  control_published: Open to Responsible Disclosure
  location: App Security section of the NextRoll Trust Center (SafeBase)
  bug_bounty_platform: null
  bug_bounty_note: >-
    No public bug-bounty program page was found on hackerone.com, bugcrowd.com or
    intigriti.com for NextRoll or AdRoll. HackerOne appears on the trust center as the
    AUDITOR of NextRoll's penetration test report, not as a public bounty host — the
    two are recorded separately here so the distinction is not lost.
  penetration_testing:
    auditor: HackerOne
    artifact: Pentest Report (gated behind a trust-center access request)
security_txt:
  published: false
  paths_probed:
  - https://www.nextroll.com/.well-known/security.txt
  - https://www.adroll.com/.well-known/security.txt
  - https://services.adroll.com/.well-known/security.txt
  - https://apidocs.nextroll.com/.well-known/security.txt
  note: >-
    None returned RFC 9116 text. www.rollworks.com returns HTTP 200 for the path but
    the body is the HubSpot marketing homepage HTML — a catch-all, not a security.txt.
other_contacts:
  data_protection_officer: dpo@nextroll.com
  support: support@nextroll.com
  privacy_requests: https://nextroll-privacy.relyance.ai
evidence:
- source: https://security.nextroll.com/
  kind: trust-center
  http_status: 200
  keywords: [responsible disclosure, security@nextroll.com, pentest report, app security]
- source: https://www.nextroll.com/trust-center
  kind: trust-page
  http_status: 200
gaps:
- No RFC 9116 security.txt on any host, so an automated scanner finds no disclosure
  contact without reading a JavaScript-rendered trust portal.
- No published disclosure policy text, scope statement, or safe-harbour language —
  only a "we are open to responsible disclosure" control and an email address.