generated: '2026-08-12' method: probed source: live probes of monetate.com, developer.monetate.com, docs.monetate.com, support.monetate.com, marketer.monetate.net and trust.monetate.com published: false security_txt: false bug_bounty: false disclosure_page: false note: >- No vulnerability disclosure surface of any kind was found. /.well-known/security.txt returns 404 on every Monetate host probed; there is no /security or /trust page on monetate.com (both 404); the SafeBase trust center at trust.monetate.com does not mention responsible disclosure or a bug bounty; and no Monetate program exists on HackerOne, Bugcrowd or Intigriti. A researcher who finds a flaw in the Engine API has no published channel to report it through other than the general contact form. This is a recorded ABSENCE — no `Security` pointer is emitted in apis.yml, because there is nothing to point at. contacts_found: - type: general contact form url: https://monetate.com/contact/ security_specific: false - type: API contact in spec metadata value: api@monetate.com source: openapi/monetate-engine-api-openapi.yml (info.contact.name) security_specific: false note: >- Recorded because it is the only email address Monetate publishes in machine-readable form. It is an API support contact, not a security contact, and the spec stores it in `info.contact.name` rather than `info.contact.email`. x-evidence: - fetched: '2026-08-12' url: https://monetate.com/.well-known/security.txt http_status: 404 - fetched: '2026-08-12' url: https://developer.monetate.com/.well-known/security.txt http_status: 404 - fetched: '2026-08-12' url: https://docs.monetate.com/.well-known/security.txt http_status: 404 - fetched: '2026-08-12' url: https://marketer.monetate.net/.well-known/security.txt http_status: 404 - fetched: '2026-08-12' url: https://monetate.com/security/ http_status: 404 - fetched: '2026-08-12' url: https://trust.monetate.com/ http_status: 200 finding: no disclosure policy, no bug bounty referenced