generated: '2026-08-01' method: searched probe: true source: https://security.nextroll.com/ policy: - https://security.nextroll.com/ contact: - security@nextroll.com contact_form: 'mailto:security@nextroll.com?subject=SafeBase Responsible Disclosure Report for NextRoll' program: type: coordinated disclosure control_published: Open to Responsible Disclosure location: App Security section of the NextRoll Trust Center (SafeBase) bug_bounty_platform: null bug_bounty_note: >- No public bug-bounty program page was found on hackerone.com, bugcrowd.com or intigriti.com for NextRoll or AdRoll. HackerOne appears on the trust center as the AUDITOR of NextRoll's penetration test report, not as a public bounty host — the two are recorded separately here so the distinction is not lost. penetration_testing: auditor: HackerOne artifact: Pentest Report (gated behind a trust-center access request) security_txt: published: false paths_probed: - https://www.nextroll.com/.well-known/security.txt - https://www.adroll.com/.well-known/security.txt - https://services.adroll.com/.well-known/security.txt - https://apidocs.nextroll.com/.well-known/security.txt note: >- None returned RFC 9116 text. www.rollworks.com returns HTTP 200 for the path but the body is the HubSpot marketing homepage HTML — a catch-all, not a security.txt. other_contacts: data_protection_officer: dpo@nextroll.com support: support@nextroll.com privacy_requests: https://nextroll-privacy.relyance.ai evidence: - source: https://security.nextroll.com/ kind: trust-center http_status: 200 keywords: [responsible disclosure, security@nextroll.com, pentest report, app security] - source: https://www.nextroll.com/trust-center kind: trust-page http_status: 200 gaps: - No RFC 9116 security.txt on any host, so an automated scanner finds no disclosure contact without reading a JavaScript-rendered trust portal. - No published disclosure policy text, scope statement, or safe-harbour language — only a "we are open to responsible disclosure" control and an email address.