TPS Engage · Vulnerability Disclosure

Tps Engage Vulnerability Disclosure

Vulnerability disclosure

TPS Engage runs a coordinated vulnerability disclosure program on Hackerone.

CompanyAdvertisingDOOHDigital BillboardsProgrammatic AdvertisingMedia BuyingOut-of-Home
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: https://seeblindspot.com/trust-and-security/
summary: >-
  Blindspot publishes a coordinated vulnerability disclosure invitation with a named
  security mailbox and an explicit safe-harbour promise, on its Trust & Security
  page. It is a policy statement rather than a program: there is no bug bounty, no
  rewards, no scope or exclusions list, no response-time commitment, and — notably —
  no /.well-known/security.txt, so an automated scanner or an agent looking for the
  RFC 9116 machine-readable pointer finds nothing and would wrongly conclude there is
  no channel at all.
program:
  published: true
  type: coordinated-disclosure
  url: https://seeblindspot.com/trust-and-security/
  contact: security@seeblindspot.com
  safe_harbor: true
  safe_harbor_quote: >-
    Researchers who report in good faith are told "we will not pursue or support legal
    action against you".
  reporting_quote: 'Blindspot asks researchers to "Report it in good faith to security@seeblindspot.com".'
bug_bounty:
  present: false
  platform: null
  detail: >-
    No HackerOne, Bugcrowd, Intigriti or self-hosted bounty program was found. No
    rewards, swag or hall of fame is published.
security_txt:
  present: false
  probed:
  - url: https://seeblindspot.com/.well-known/security.txt
    status: 404
    checked: '2026-08-13'
  - url: https://rtb.network.tpsengage.com/.well-known/security.txt
    status: 404
    checked: '2026-08-13'
  - url: https://api.tpsengage.com/.well-known/security.txt
    status: 404
    checked: '2026-08-13'
  detail: >-
    RFC 9116 security.txt is absent on every probed host even though a security
    mailbox exists and is published in prose. Publishing
    /.well-known/security.txt with Contact, Policy and Preferred-Languages would make
    the existing channel machine-discoverable at effectively zero cost — the single
    cheapest security-posture fix available to this provider.
scope:
  published: false
  detail: No in-scope/out-of-scope asset list, no testing rules of engagement, no response SLA.
observed:
- url: https://seeblindspot.com/trust-and-security/
  status: 200
  checked: '2026-08-13'
gaps:
- No /.well-known/security.txt on any host.
- No disclosure timeline or acknowledgement commitment.
- No scope definition or rules of engagement for researchers.
- No bug bounty or recognition program.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tps-engage-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.