generated: '2026-08-13' method: searched probe: true source: https://www.brandwatch.com/legal/information-security/ policy: - https://www.brandwatch.com/legal/information-security/ policy_note: >- Section 11, "Vulnerability Disclosure", of the Brandwatch Security Programme page. It is a prose section of a broader security page, not a standalone disclosure policy URL and not an RFC 9116 security.txt. contact: - security@brandwatch.com contact_note: >- Published on the Information Security page behind Cloudflare email obfuscation; decoded from the page's data-cfemail attribute on 2026-08-13. privacy@brandwatch.com is published alongside it for privacy and compliance matters. bug_bounty: program: false platform: null statement: >- "We do not have an official bug bounty programme (nor do we expect to create one in the near future). This means we do not have standing financial or personnel resources dedicated to handling unsolicited bug reports." compensation: discretionary compensation_note: >- "we may choose to provide compensation for these submissions where appropriate ... our assessment of what's appropriate may differ from yours, and we unfortunately cannot negotiate reward amounts." accepts_reports: true coordinated_disclosure: requested: true statement: >- "Vulnerabilities found are not confidential, but we would ask that you not publicly disclose the things you find without giving us time to remedy any issues." embargo_period: unspecified safe_harbor: not stated security_testing: vulnerability_testing: at least monthly penetration_testing: third-party, intensive manual and automated source: https://www.brandwatch.com/legal/information-security/ security_txt: served: false probed: - url: https://www.brandwatch.com/.well-known/security.txt status: 404 - url: https://developers.brandwatch.com/.well-known/security.txt status: 404 - url: https://api.brandwatch.com/.well-known/security.txt status: 401 note: >- Brandwatch has both a disclosure policy and a security@ contact but does not publish them at the machine-readable RFC 9116 location, so an automated scanner finds nothing. This is a one-file fix for the provider. evidence: - source: https://www.brandwatch.com/legal/information-security/ status: 200 kind: disclosure-policy-section keywords: - vulnerability disclosure - bug bounty - security@brandwatch.com - responsible disclosure - source: https://www.brandwatch.com/.well-known/security.txt status: 404 kind: security.txt-absent