generated: '2026-08-13' method: searched probe: true source: https://www.thetradedesk.com/trust/report-a-vulnerability policy: - https://www.thetradedesk.com/trust/report-a-vulnerability program: platform: Bugcrowd type: vulnerability disclosure program submission_form: https://bugcrowd.com/b0380ed1-525e-43db-8315-f66fd4c8f162/external/report note: The Report a Vulnerability page embeds a Bugcrowd external submission widget (bugcrowd-program script and report endpoint present in the served HTML). No public bounty table, scope document or response SLA is published, so this is recorded as a disclosure program rather than a bounty program. contact: [] contact_note: No security@ address and no security.txt. /.well-known/security.txt returns 404 on every Trade Desk host probed (www, open, partner, api, auth, and the adsrvr.org data hosts). The Bugcrowd form is the only published intake channel. security_bulletins: https://www.thetradedesk.com/trust/security-bulletins evidence: - source: https://www.thetradedesk.com/trust/report-a-vulnerability kind: disclosure-page http_status: 200 fetched: '2026-08-13' found: - bugcrowd.com/b0380ed1-525e-43db-8315-f66fd4c8f162/external/report - bugcrowd-program script tag - source: https://www.thetradedesk.com/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-08-13' - source: https://hackerone.com/thetradedesk kind: bounty-platform http_status: 404 fetched: '2026-08-13'