Taboola · Vulnerability Disclosure
Taboola Vulnerability Disclosure
Vulnerability disclosure
Taboola publishes a full, standalone Vulnerability Disclosure Policy — not a paragraph inside the privacy policy, which is what a prior round had recorded. It carries a brand promise, an explicit scope list, a safe-harbour legal posture, a named reporting mailbox, a stated response SLA and a discretionary reward program. There is no HackerOne or Bugcrowd program (both /taboola pages return 404) and no security.txt is served on any Taboola host.
Taboola runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
AdvertisingNative AdvertisingDiscoveryPerformance MarketingAdTechRealizeBackstageRecommendationPublishersProgrammatic
Program: Hackerone
Disclosure Policy
Security Contact
Contact
bountyprogram@taboola.com