Blackstone · Vulnerability Disclosure

Blackstone Vulnerability Disclosure

Vulnerability disclosure

Blackstone runs a published Responsible Vulnerability Disclosure programme covering applications and systems on Blackstone-owned domains. Reports go to the Blackstone cybersecurity team by encrypted email; the team acknowledges properly submitted reports within five business days. It is a disclosure programme, not a bug bounty — Blackstone states it does not offer rewards or compensation.

Blackstone publishes a vulnerability disclosure policy for reporting security issues.

Alternative AssetsFinanceInvestment ManagementPrivate EquityReal-EstateFortune 500
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

blackstone-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-10'
method: searched
source: https://www.blackstone.com/responsible-vulnerability-disclosure/
provider: Blackstone
providerId: blackstone
description: >-
  Blackstone runs a published Responsible Vulnerability Disclosure programme covering
  applications and systems on Blackstone-owned domains. Reports go to the Blackstone
  cybersecurity team by encrypted email; the team acknowledges properly submitted reports within
  five business days. It is a disclosure programme, not a bug bounty — Blackstone states it does
  not offer rewards or compensation.
program:
  published: true
  type: vulnerability-disclosure-policy
  bug_bounty: false
  rewards: false
  platform: none
  url: https://www.blackstone.com/responsible-vulnerability-disclosure/
  scope: Applications and systems under a Blackstone-owned domain
  submission_channel: email
  encryption_required: true
  acknowledgement_sla: 5 business days
  contact_email: null
  contact_email_note: >-
    The programme page publishes a cybersecurity-team address, but the address was masked in
    every index snippet available to this pass and the page itself could not be fetched directly
    (see x-evidence). Not recorded rather than guessed.
  safe_harbor: unknown
security_txt:
  served: false
  note: >-
    No RFC 9116 security.txt is served on any Blackstone host — the policy exists only as an HTML
    page. Publishing /.well-known/security.txt with a Policy and Contact line pointing at this
    same page would make the programme machine-discoverable at zero policy cost. This is the
    provider's to fix.
x-evidence:
  - url: https://www.blackstone.com/responsible-vulnerability-disclosure/
    http_status: 403
    fetched: '2026-08-10'
    note: >-
      Direct fetch blocked. www.blackstone.com returns 403 with `cf-mitigated: challenge` for
      every non-browser client, including full browser header sets and archive proxies. The
      policy content recorded above was read from a public search index that had crawled the
      page, not from our own fetch. Confidence in the programme's existence: high (the URL is a
      live Blackstone-owned path with indexed policy text). Confidence in the exact field values:
      medium.
  - url: https://www.blackstone.com/.well-known/security.txt
    http_status: 403
    fetched: '2026-08-10'
  - url: https://login.bx.com/.well-known/security.txt
    http_status: 405
    fetched: '2026-08-10'
  - url: https://ir.blackstone.com/.well-known/security.txt
    http_status: 200
    fetched: '2026-08-10'
    note: Soft 200 — 11-byte "Invalid key" body, not a security.txt.
confidence: medium
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com