Stagwell · Vulnerability Disclosure
Stagwell Vulnerability Disclosure
Vulnerability disclosure
Stagwell runs a coordinated vulnerability disclosure program on Hackerone.
MarketingAdvertisingMediaMarTechInfluencer MarketingMarket ResearchCreator EconomyPublic RelationsConsumer InsightsHolding Company
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-12'
method: searched
source: https://influencermarketing.ai/security/
note: >-
probe-security-programs.py returned vdp=none: no /.well-known/security.txt is
served on any Stagwell host, and no HackerOne, Bugcrowd or Intigriti program
page exists for Stagwell or its brands. The program recorded here was found by
reading the IMAI Security Center page — IMAI / InfluencerMarketing.ai is a
Stagwell (NASDAQ: STGW) company via the July 2024 LEADERS acquisition. It is a
self-run program described in prose: there is no published policy document, no
scope statement, no safe-harbour language, no severity/reward table, and no
dedicated intake address or form. Stagwell itself, at the holding-company
level, publishes no vulnerability disclosure program at all.
program:
exists: true
operator: IMAI / InfluencerMarketing.ai (Stagwell)
url: https://influencermarketing.ai/security/
type: bug-bounty
managed_platform: null
responsible_disclosure: true
rewards: true
reward_details: >-
"Help us identify vulnerabilities, strengthen our platform, and earn rewards
for your discoveries." No amounts, severity bands or payout table published.
scope: not published
safe_harbour: not published
intake:
security_txt: false
dedicated_email: null
form: null
note: >-
No submission channel is named on the page. The only contact route on the
site is the general support address and the /contact-us/ form.
statements:
- >-
Proactive Detection — advanced threat intelligence systems continuously
monitor infrastructure for vulnerabilities; regular penetration testing and
vulnerability assessments.
- >-
Transparent Disclosure — a responsible disclosure program encouraging
ethical hackers to report vulnerabilities, with verification and
remediation of all reported issues affecting the platform or customer data.
- >-
Rapid Response — high-severity findings trigger a formal incident response
protocol (isolation, investigation, remediation); business continuity and
disaster recovery plans are maintained and regularly tested.
security_txt:
served: false
probed:
- url: https://influencermarketing.ai/.well-known/security.txt
status: 404
- url: https://www.stagwellglobal.com/.well-known/security.txt
status: 404
- url: https://www.themarketingcloud.com/.well-known/security.txt
status: 404
recommendation: >-
Publish an RFC 9116 /.well-known/security.txt on influencermarketing.ai and
stagwellglobal.com naming a Contact and a Policy URL. The program exists; it is
simply not machine-discoverable, which is the difference between a researcher
finding the intake in seconds and not finding it at all.
x-evidence:
fetched: '2026-08-12'
probes:
- url: https://influencermarketing.ai/security/
status: 200
- url: https://influencermarketing.ai/.well-known/security.txt
status: 404