generated: '2026-08-12' method: searched source: https://www.microsoft.com/.well-known/security.txt api: Digital Platform API provider_hosted: false ownership_note: >- AppNexus/Xandr no longer runs a disclosure program of its own. appnexus.com and xandr.com serve no security.txt (see well-known/appnexus-well-known.yml - both domains 301 to about.ads.microsoft.com, whose SPA answers 200 with an HTML shell for every path). Xandr has been a Microsoft product line since the 2022 acquisition, and the Microsoft Security Response Center is the disclosure channel that actually covers the Xandr / Microsoft Monetize online services. The program below is therefore the PARENT company's, recorded as such rather than attributed to an appnexus.com surface. program: name: Microsoft Security Response Center (MSRC) operator: Microsoft Corporation report_url: https://msrc.microsoft.com/report/vulnerability report_url_status: 200 policy_url: https://www.microsoft.com/en-us/msrc/cvd security_txt: https://www.microsoft.com/.well-known/security.txt security_txt_status: 200 security_txt_host: www.microsoft.com self_hosted_on_provider_domain: false bug_bounty: present: true name: Microsoft Bug Bounty Program url: https://www.microsoft.com/en-us/msrc/bounty url_status: 200 platform: self-operated (MSRC), not HackerOne/Bugcrowd/Intigriti note: >- Microsoft's Online Services bounty scope is the one that would cover the Monetize / Invest platform surface. Xandr-specific scope wording is not published separately. probes: - url: https://api.appnexus.com/.well-known/security.txt status: 404 - url: https://www.appnexus.com/.well-known/security.txt status: 301 resolved_status: 200 verdict: miss reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text - url: https://www.xandr.com/.well-known/security.txt status: 301 resolved_status: 200 verdict: miss reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text - url: https://www.microsoft.com/.well-known/security.txt status: 200 verdict: hit scope: parent company - url: https://msrc.microsoft.com/report/vulnerability status: 200 verdict: hit scope: parent company gap: finding: >- A researcher who finds a flaw in api.appnexus.com has no machine-discoverable route to report it from that host. Publishing an RFC 9116 security.txt on api.appnexus.com pointing at MSRC would close this with one file.