name: TripleLift Vulnerability Disclosure description: >- Probe for a coordinated vulnerability disclosure programme. Nothing was found. TripleLift publishes no security.txt on any host, no /security or /vulnerability-disclosure page, and no bug-bounty programme was located on HackerOne, Bugcrowd or Intigriti. This file records a measured absence — it is not a claim that TripleLift lacks an internal process, only that a researcher who finds a vulnerability has no published channel to report it through. generated: '2026-08-12' method: probed source: live probes of TripleLift hosts and bug-bounty platform directories, 2026-08-12 program: published: false type: none security_txt: false policy_url: null contact: null bug_bounty: null safe_harbor: null hall_of_fame: null pgp_key: null probes: - url: https://triplelift.com/.well-known/security.txt status: 404 - url: https://docs.triplelift.com/.well-known/security.txt status: 404 - url: https://supply-docs.triplelift.com/.well-known/security.txt status: 404 - url: https://tlx.3lift.com/.well-known/security.txt status: 404 - url: https://api.triplelift.com/.well-known/security.txt status: 400 - url: https://reporting-api.triplelift.net/.well-known/security.txt status: 401 - url: https://console.triplelift.com/.well-known/security.txt status: 200 note: SPA catch-all returning the console's HTML shell for every path. Not a security.txt. Counted as a miss. - url: https://triplelift.com/security/ status: 404 - url: https://triplelift.com/security-policy/ status: 404 - url: https://triplelift.com/vulnerability-disclosure/ status: 404 fallback_contact: url: https://triplelift.com/contact-us/ status: 200 note: >- A general sales/contact form is the only published route. There is no security@ address, no disclosure policy and no safe-harbor statement. gap: summary: >- TripleLift sits in the OpenRTB supply chain handling user identifiers, consent strings and publisher revenue data, and operates an Auth0 tenant with wildcard API scopes — and offers a security researcher no published way to report a finding. A single /.well-known/security.txt naming a contact and a policy URL would close this; it is the cheapest unclaimed item on TripleLift's entire developer surface.