ZoomInfo · Vulnerability Disclosure

Zoominfo Vulnerability Disclosure

Vulnerability disclosure

ZoomInfo runs a bug bounty program and publishes a security contact address. Verified from ZoomInfo's own public security page plus a live probe of the bug bounty platform handle.

ZoomInfo runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

B2BB2B DataCompany DataContact DatabaseContactsDataLead GenerationMarketing IntelligenceSales IntelligenceIntent DataGo-To-MarketData EnrichmentAI AgentsMCP
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emailsecurity@zoominfo.com
Contact
noteThe address appears in the zoominfo.com CAA iodef record as well as on the security page, so it is machine-discoverable even though no security.txt is served.
Contact
sourceshttps://www.zoominfo.com/about/securityDNS CAA record for zoominfo.com: 0 iodef "mailto:security@zoominfo.com"

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.zoominfo.com/about/security
provider: ZoomInfo
providerId: zoominfo
description: >-
  ZoomInfo runs a bug bounty program and publishes a security contact address. Verified from ZoomInfo's
  own public security page plus a live probe of the bug bounty platform handle.

program:
  exists: true
  type: bug-bounty
  platform: HackerOne
  handle: zoominfo
  url: https://hackerone.com/zoominfo
  probe:
    url: https://hackerone.com/zoominfo
    http_status: 200
    control_probe: 'https://hackerone.com/zzzznotarealprogram-xyz -> 404 (confirms 200 means the handle resolves)'
    note: The HackerOne page itself requires JavaScript, so program scope and reward table were not read.
    fetched: '2026-08-13'
  provider_statement: >-
    "ZoomInfo accepts reporting of flaws in our perimeter security by ethical hackers that report on such
    weaknesses and vulnerabilities."
  provider_statement_source: https://www.zoominfo.com/about/security (section 8.5, Bug Bounty Program)
  rules_page:
    url: https://www.zoominfo.com/trust-center/bug-bounty-program
    http_status: 403
    note: Linked from the security page but blocked to non-browser requests by bot protection.

contact:
  email: security@zoominfo.com
  sources:
    - https://www.zoominfo.com/about/security
    - 'DNS CAA record for zoominfo.com: 0 iodef "mailto:security@zoominfo.com"'
  note: >-
    The address appears in the zoominfo.com CAA iodef record as well as on the security page, so it is
    machine-discoverable even though no security.txt is served.

security_txt:
  served: false
  probes:
    - {url: 'https://www.zoominfo.com/.well-known/security.txt', status: 403}
    - {url: 'https://zoominfo.com/.well-known/security.txt', status: 403}
    - {url: 'https://api.zoominfo.com/.well-known/security.txt', status: 401}
    - {url: 'https://docs.zoominfo.com/.well-known/security.txt', status: 404}
    - {url: 'https://developer.zoominfo.com/.well-known/security.txt', status: 404}
  gap: >-
    A bug bounty program and a published security address exist, but neither is discoverable via RFC 9116.
    Serving a security.txt at https://www.zoominfo.com/.well-known/security.txt with the existing
    Contact and Policy URLs would close this with no new policy work.

vulnerability_management:
  source: https://www.zoominfo.com/about/security
  claims:
    - Established vulnerability testing schedule with results reported into an Agile task tracking system.
    - Regular scanning; critical vulnerabilities addressed upon discovery.
    - Risk review with an assigned risk level and priority based on impact.