Stagwell · Vulnerability Disclosure

Stagwell Vulnerability Disclosure

Vulnerability disclosure

Stagwell runs a coordinated vulnerability disclosure program on Hackerone.

MarketingAdvertisingMediaMarTechInfluencer MarketingMarket ResearchCreator EconomyPublic RelationsConsumer InsightsHolding Company
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

stagwell-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-12'
method: searched
source: https://influencermarketing.ai/security/
note: >-
  probe-security-programs.py returned vdp=none: no /.well-known/security.txt is
  served on any Stagwell host, and no HackerOne, Bugcrowd or Intigriti program
  page exists for Stagwell or its brands. The program recorded here was found by
  reading the IMAI Security Center page — IMAI / InfluencerMarketing.ai is a
  Stagwell (NASDAQ: STGW) company via the July 2024 LEADERS acquisition. It is a
  self-run program described in prose: there is no published policy document, no
  scope statement, no safe-harbour language, no severity/reward table, and no
  dedicated intake address or form. Stagwell itself, at the holding-company
  level, publishes no vulnerability disclosure program at all.
program:
  exists: true
  operator: IMAI / InfluencerMarketing.ai (Stagwell)
  url: https://influencermarketing.ai/security/
  type: bug-bounty
  managed_platform: null
  responsible_disclosure: true
  rewards: true
  reward_details: >-
    "Help us identify vulnerabilities, strengthen our platform, and earn rewards
    for your discoveries." No amounts, severity bands or payout table published.
  scope: not published
  safe_harbour: not published
  intake:
    security_txt: false
    dedicated_email: null
    form: null
    note: >-
      No submission channel is named on the page. The only contact route on the
      site is the general support address and the /contact-us/ form.
  statements:
    - >-
      Proactive Detection — advanced threat intelligence systems continuously
      monitor infrastructure for vulnerabilities; regular penetration testing and
      vulnerability assessments.
    - >-
      Transparent Disclosure — a responsible disclosure program encouraging
      ethical hackers to report vulnerabilities, with verification and
      remediation of all reported issues affecting the platform or customer data.
    - >-
      Rapid Response — high-severity findings trigger a formal incident response
      protocol (isolation, investigation, remediation); business continuity and
      disaster recovery plans are maintained and regularly tested.
security_txt:
  served: false
  probed:
    - url: https://influencermarketing.ai/.well-known/security.txt
      status: 404
    - url: https://www.stagwellglobal.com/.well-known/security.txt
      status: 404
    - url: https://www.themarketingcloud.com/.well-known/security.txt
      status: 404
recommendation: >-
  Publish an RFC 9116 /.well-known/security.txt on influencermarketing.ai and
  stagwellglobal.com naming a Contact and a Policy URL. The program exists; it is
  simply not machine-discoverable, which is the difference between a researcher
  finding the intake in seconds and not finding it at all.
x-evidence:
  fetched: '2026-08-12'
  probes:
    - url: https://influencermarketing.ai/security/
      status: 200
    - url: https://influencermarketing.ai/.well-known/security.txt
      status: 404