Zemanta · Vulnerability Disclosure

Zemanta Vulnerability Disclosure

Vulnerability disclosure

Zemanta publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyAdvertisingNative AdvertisingProgrammaticDSPAdTechContent RecommendationMarketingCampaign ManagementDemand Side PlatformMedia Buying
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://www.outbrain.com/security/bug-bounty/

Source

Vulnerability Disclosure

zemanta-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-12'
method: searched
probe: true
source: https://oneapi.zemanta.com/.well-known/security.txt (302) -> https://www.outbrain.com/.well-known/security.txt (200)
policy:
- https://www.outbrain.com/security/bug-bounty/
contact:
- https://www.outbrain.com/security/bug-bounty/
program:
  published: true
  type: bug-bounty
  operator: Outbrain (parent company of Zemanta / Teads DSP)
  contact: https://www.outbrain.com/security/bug-bounty/
  policy: https://www.outbrain.com/security/bug-bounty/
  security_txt: well-known/zemanta-security.txt
  rfc9116: true
  rfc9116_completeness:
    contact: true
    policy: true
    expires: false
    encryption: false
    preferred_languages: false
    acknowledgments: false
    canonical: false
    note: >-
      Only Contact and Policy are present. RFC 9116 requires an Expires field; this document
      omits it, so it is a non-conformant security.txt in the strict sense even though the
      two fields it does carry are actionable.
evidence:
- source: well-known/zemanta-security.txt
  kind: security.txt (harvested 2026-08-12)
- url: https://oneapi.zemanta.com/.well-known/security.txt
  http_status: 302
  redirect_to: https://www.outbrain.com/.well-known/security.txt
  fetched: '2026-08-12'
- url: https://www.outbrain.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain; charset=utf-8
  bytes: 110
  fetched: '2026-08-12'
  body: |
    Contact: https://www.outbrain.com/security/bug-bounty/
    Policy: https://www.outbrain.com/security/bug-bounty/
note: >-
  The disclosure surface for the Teads DSP API is the parent company's. The Zemanta API host
  itself resolves /.well-known/security.txt by 302-redirecting to Outbrain's document, which
  is the provider's own act of delegation rather than an inference on our part. The bug-bounty
  landing page could not be read directly with a scripted client — www.outbrain.com answers
  406 Not Acceptable to non-browser user agents — so the program's scope and reward terms are
  recorded as unverified.
unverified:
- Whether oneapi.zemanta.com / dsp.outbrain.com are in scope for the bug-bounty program.
- Reward terms, safe-harbour language and disclosure timelines.