generated: '2026-08-13' method: searched source: >- https://mention.com/en/terms-and-conditions/#security-policy, /.well-known/security.txt probes on mention.com and api.mention.com, and https://www.agorapulse.com/security/ (parent brand) summary: >- Mention publishes a Security Policy but NO vulnerability disclosure program of its own: no security.txt, no security contact address, no bug bounty, no reporting instructions and no safe harbour statement. The nearest reachable program belongs to Agorapulse, Mention's parent brand, and it is a PRIVATE (invitation-only) HackerOne program that does not name Mention in scope. mention_program: published: false security_txt: false policy_url: https://mention.com/en/terms-and-conditions/#security-policy policy_covers: >- Hosting, data residency, availability goal, application stack, access control, backups, deployment process, privacy governance, personnel and breach notification. It does not tell a researcher how to report a vulnerability. reporting_channel: none published security_contact: none published bug_bounty: none safe_harbour: false breach_notification: stated: true detail: >- "Mention has established a routine for managing personal data breaches with an escalation program ... report about an incident within 72 hours to the data authority in France (CNIL)." This is regulator notification, not researcher intake. generic_contacts: - info@mention.com - gdpr@mention.com note: >- Neither address is presented as a security channel; they are the general and privacy contacts. parent_brand_program: company: Agorapulse relationship: >- Mention is sold by Agorapulse SAS (General Terms of Sale, version Apr 15, 2025) and mention.com routes its trial and demo funnels to social.agorapulse.com. This entry is recorded for context only — it is NOT credited to Mention, because Agorapulse's security page does not name Mention as a covered product and mention.com does not link to it. url: https://www.agorapulse.com/security/ security_contact: security-trust@agorapulse.com bug_bounty: platform: HackerOne public: false quote: >- "Potential vulnerabilities can be reported through our private bug bounty program running on HackerOne." trust_center: https://www.agorapulse.com/trust-center/ status_page: https://status.agorapulse.com/ evidence: - url: https://mention.com/.well-known/security.txt http_status: 404 fetched: '2026-08-13' - url: https://api.mention.com/.well-known/security.txt http_status: 404 fetched: '2026-08-13' - url: https://mention.com/en/terms-and-conditions/ http_status: 200 fetched: '2026-08-13' note: Contains a #security-policy section, version Apr 22, 2022. recommendations: - Serve an RFC 9116 /.well-known/security.txt on mention.com and api.mention.com with Contact, Policy and Expires. - Publish a reporting address and a safe-harbour statement alongside the existing Security Policy. - State whether the Agorapulse HackerOne program covers Mention, so researchers know where to send findings. maintainers: - FN: Kin Lane email: kin@apievangelist.com