generated: '2026-07-19' method: searched probe: true note: >- Criteo publishes an RFC 9116 security.txt with a security contact on both the API host and the corporate site. No public bug-bounty (HackerOne/Bugcrowd/ Intigriti) program or standalone disclosure policy page was found. contact: - security@criteo.com policy: [] security_txt: - https://api.criteo.com/.well-known/security.txt - https://www.criteo.com/.well-known/security.txt evidence: - source: well-known/hooklogic-criteo-security.txt kind: security.txt detail: 'Contact: security@criteo.com; Preferred-Languages: en'