YouScan · Vulnerability Disclosure

Youscan Vulnerability Disclosure

Vulnerability disclosure

YouScan publishes a responsible-disclosure channel through its SafeBase-hosted trust center rather than at /.well-known/security.txt (all four YouScan hosts 404 or soft-200 that path — see well-known/youscan-well-known.yml). The trust center carries an explicit invitation — "If you think you may have discovered a vulnerability, please send us a note" — wired to a dedicated reporting mailbox.

YouScan runs a coordinated vulnerability disclosure program on Hackerone.

CompanySocial Media ListeningSocial IntelligenceConsumer InsightsSentiment AnalysisMedia MonitoringAnalyticsArtificial Intelligence
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: https://trust.youscan.io/
description: >-
  YouScan publishes a responsible-disclosure channel through its SafeBase-hosted trust center
  rather than at /.well-known/security.txt (all four YouScan hosts 404 or soft-200 that path —
  see well-known/youscan-well-known.yml). The trust center carries an explicit invitation —
  "If you think you may have discovered a vulnerability, please send us a note" — wired to a
  dedicated reporting mailbox.
program:
  published: true
  type: responsible-disclosure
  platform: SafeBase Trust Center
  url: https://trust.youscan.io/
  bug_bounty: false
  bounty_platform: null
  note: >-
    No HackerOne, Bugcrowd or Intigriti program was found. This is an email-based responsible
    disclosure invitation, not a paid bounty program.
contacts:
- purpose: vulnerability-report
  email: security@youscan.io
  channel: mailto
  evidence: >-
    "Report issue" link on https://trust.youscan.io/ resolves to
    mailto:security@youscan.io?subject=SafeBase Responsible Disclosure Report for YouScan
- purpose: trust-center-support
  email: trust@youscan.io
  channel: mailto
  evidence: '"Contact support" link and footer address on https://trust.youscan.io/'
- purpose: general-support
  email: support@youscan.io
  channel: mailto
  evidence: https://help.youscan.io/en/articles/2754452-how-to-use-youscan-api
policy:
  document_published: false
  safe_harbor_stated: false
  response_sla: null
  encryption_key: null
  note: >-
    No public disclosure policy text, safe-harbor statement, scope definition or PGP key was
    found. The published surface is the reporting address itself. A security.txt at
    https://youscan.io/.well-known/security.txt naming this Contact and a Policy URL would
    close the gap and is the single cheapest fix available here.
evidence:
- url: https://trust.youscan.io/
  status: 200
  found:
  - mailto:security@youscan.io (Responsible Disclosure Report)
  - mailto:trust@youscan.io
  - Pentest Report (gated behind trust-center access request)
  - Incident Response — Designated Response Personnel, Incident Reporting Process
- url: https://youscan.io/.well-known/security.txt
  status: 404
- url: https://api.youscan.io/.well-known/security.txt
  status: 404
checked: '2026-08-13'