TripleLift · Vulnerability Disclosure

Triplelift Vulnerability Disclosure

Vulnerability disclosure

Probe for a coordinated vulnerability disclosure programme. Nothing was found. TripleLift publishes no security.txt on any host, no /security or /vulnerability-disclosure page, and no bug-bounty programme was located on HackerOne, Bugcrowd or Intigriti. This file records a measured absence — it is not a claim that TripleLift lacks an internal process, only that a researcher who finds a vulnerability has no published channel to report it through.

TripleLift runs a coordinated vulnerability disclosure program on Hackerone.

Programmatic AdvertisingNative AdvertisingAd ExchangeOpenRTBHeader BiddingConnected TVSupply Side PlatformDemand-Side PlatformGraphQLAdTechPublisher ReportingReal-Time Bidding
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

triplelift-vulnerability-disclosure.yml Raw ↑
name: TripleLift Vulnerability Disclosure
description: >-
  Probe for a coordinated vulnerability disclosure programme. Nothing was found.
  TripleLift publishes no security.txt on any host, no /security or
  /vulnerability-disclosure page, and no bug-bounty programme was located on
  HackerOne, Bugcrowd or Intigriti. This file records a measured absence — it is not
  a claim that TripleLift lacks an internal process, only that a researcher who
  finds a vulnerability has no published channel to report it through.
generated: '2026-08-12'
method: probed
source: live probes of TripleLift hosts and bug-bounty platform directories, 2026-08-12
program:
  published: false
  type: none
  security_txt: false
  policy_url: null
  contact: null
  bug_bounty: null
  safe_harbor: null
  hall_of_fame: null
  pgp_key: null
probes:
  - url: https://triplelift.com/.well-known/security.txt
    status: 404
  - url: https://docs.triplelift.com/.well-known/security.txt
    status: 404
  - url: https://supply-docs.triplelift.com/.well-known/security.txt
    status: 404
  - url: https://tlx.3lift.com/.well-known/security.txt
    status: 404
  - url: https://api.triplelift.com/.well-known/security.txt
    status: 400
  - url: https://reporting-api.triplelift.net/.well-known/security.txt
    status: 401
  - url: https://console.triplelift.com/.well-known/security.txt
    status: 200
    note: SPA catch-all returning the console's HTML shell for every path. Not a security.txt. Counted as a miss.
  - url: https://triplelift.com/security/
    status: 404
  - url: https://triplelift.com/security-policy/
    status: 404
  - url: https://triplelift.com/vulnerability-disclosure/
    status: 404
fallback_contact:
  url: https://triplelift.com/contact-us/
  status: 200
  note: >-
    A general sales/contact form is the only published route. There is no security@
    address, no disclosure policy and no safe-harbor statement.
gap:
  summary: >-
    TripleLift sits in the OpenRTB supply chain handling user identifiers, consent
    strings and publisher revenue data, and operates an Auth0 tenant with wildcard
    API scopes — and offers a security researcher no published way to report a
    finding. A single /.well-known/security.txt naming a contact and a policy URL
    would close this; it is the cheapest unclaimed item on TripleLift's entire
    developer surface.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/triplelift-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.