Our latest posts on digital marketing.
Access to guides, case studies, webinars & more.
Develop your knowledge at your own pace with Mapp learning tools!

Sign Up for Our Newsletter

Vulnerability Disclosure Policy

Mapp welcomes reports from security researchers and customers who discover vulnerabilities in our products or infrastructure.

Scope

This policy covers the products and services Mapp operates or distributes: the Mapp Cloud platform, the Mapp Mobile SDK, the Mapp Website Pixel, connectors we publish for customer installation, and the mapp.com web presence.

Outside it are services operated by third parties, findings produced only by an automated scanner without demonstrated impact, missing hardening headers with no exploitable consequence, and social engineering of our staff or customers.

Reporting

Send reports to security@mapp.com, in English, with enough detail to reproduce the issue: the affected product, domain or version, what an attacker could achieve, and how we can reach you. A finished exploit or a severity rating is not required.

We acknowledge reports promptly, share an initial assessment once we have triaged the issue, and keep you informed of progress until it is closed.

What we ask

Report privately and give us the opportunity to remediate before any publication. Stop once you have shown that the issue exists. Do not access, modify or delete data that is not your own, and do not retain personal data you encounter; if you come across personal data, stop and tell us. Avoid any action that could degrade our services.

Safe harbor

Mapp will not pursue legal action against research conducted in good faith and in line with this policy. If a third party takes action over research that met this policy, we will make that authorisation clear.

Recognition

This is not a bug bounty programme. We do not offer financial rewards or other compensation.

Remediation and disclosure

We validate every report and remediate confirmed vulnerabilities across our services and released components. Because vulnerability details can be exploited within hours of publication, we disclose in stages: an initial advisory once a fix is available, further technical detail once customers have had the opportunity to update. In duly justified cases, where we consider the security risks of publication to outweigh the benefits, we delay publication until affected customers have been given the possibility to apply the update, as provided for under the EU Cyber Resilience Act.

Coordination

We agree disclosure timing with the reporter case by case, taking into account the severity of the issue and the time customers need to apply an update.

Contact and updates

Our contact details are also published at https://mapp.com/.well-known/security.txt in the format described in RFC 9116. The effective date of this document tells you which version you are reading.