Choice Hotels · Vulnerability Disclosure
Choice Hotels Vulnerability Disclosure
Vulnerability disclosure
Choice Hotels runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
TravelUnited StatesHospitalityHotelsBookingReservationsDistributionFranchisingLoyalty
Program: Hackerone
Disclosure Policy
Security Contact
Contact
responsibledisclosure@choicehotels.com
Source
Vulnerability Disclosure
generated: '2026-07-28'
method: searched
source: https://www.choicehotels.com/legal/responsible-disclosure
probe: true
name: Choice Hotels International Responsible Disclosure / Vulnerability Disclosure
Policy
policy:
- https://www.choicehotels.com/legal/responsible-disclosure
contact:
- responsibledisclosure@choicehotels.com
contact_channel: email
bug_bounty:
offered: false
verbatim: Please note, Choice Hotels International does not currently offer a "bug
bounty" program; thus, we extend no offer of compensation/reward or public recognition
for submittal of potential vulnerabilities.
platform: null
safe_harbor:
offered: true
verbatim: We will not pursue legal action, nor initiate a complaint to law enforcement,
against the finder/researcher operating in good faith. However, Choice Hotels International
reserves all legal rights in the event of non-compliance to the Guidelines for
Operating in Good Faith follow included in the Policy.
scope:
in_scope_statement: any product, system, or asset belonging to us
out_of_scope:
- Social Engineering, Such as Attempts to Steal Cookies, Fake LogIn Pages to Collect
Credentials, and Phishing
- Resource Exhaustion Attacks
- Physical Testing
- Denial of Service Attacks
response:
acknowledgement_sla: five business days
verbatim: When a report is received by the Information Security Team, an acknowledgement
will be sent in reply to the sender within five business days. A follow-on request
for further information may be sent as needed. After validation/verification of
a vulnerability, a follow-up reply will be sent to the sender.
disclosure_timeframe: No fixed embargo window is published. Choice states it "will
not negotiate in response to a threat" and asks researchers to "allow us a reasonable
amount of time for both the validation/verification and the resolution of the vulnerability
before taking action to make it public."
third_party_notification: Reporting of vulnerability information to other third parties/vendors
will be determined at the discretion of Choice Hotels International.
submission_format: A detailed description of the vulnerability — tools utilized, target,
processes, and results — with pertinent artifacts attached. Proposed remediation
is welcomed but not required.
good_faith_guidelines:
- Be respectful of existing applications; avoid privacy violations, destruction of
data, and interruption or degradation of services (including denial of service)
- Do not access or modify Choice data or stakeholder data
- Contact Choice immediately if stakeholder data is encountered; do not view, alter,
destroy, save, share, store, transfer or otherwise compromise it, and purge any
local information upon reporting
- Stop all activity and contact Choice immediately if personal information (names,
addresses, email addresses, loyalty account numbers, unique identifiers, credit
card numbers) is encountered
- Do not generate fraudulent financial transactions
- Do not violate federal, state or international laws or regulations in any jurisdiction
where assets/data/systems reside, data traffic is routed, research is conducted,
or data subjects reside
- Share the security and/or privacy issue with Choice
security_txt:
published: false
note: No RFC 9116 /.well-known/security.txt is served on any Choice Hotels host.
See well-known/choice-hotels-well-known.yml for the full probe table. The policy
is published as an HTML legal page only, so automated discovery of the disclosure
channel is not possible.
evidence:
- source: https://www.choicehotels.com/legal/responsible-disclosure
kind: disclosure-policy-page
status: 200
note: Live page is unreachable to non-browser tooling — the Akamai edge terminates
HTTP/2 with INTERNAL_ERROR for automated clients (recorded HTTP 000). Content
verified against the Internet Archive capture below, which returns the same page
under the canonical URL.
- source: http://web.archive.org/web/20260709002042/https://www.choicehotels.com/legal/responsible-disclosure
kind: archive-capture
status: 200
captured: '2026-07-09'
notes: |
This is the first genuinely public, security-relevant program surface found on any
Choice Hotels property. It is a policy-and-mailbox VDP: no bug bounty, no HackerOne
/ Bugcrowd / Intigriti program, no security.txt, no PGP key, and no published
remediation SLA — only a five-business-day acknowledgement commitment. It does not
change the provider's API posture (still no public API, no developer portal, no
machine-readable contract) but it is a real, verifiable commitment that the round-1
review did not surface, because www.choicehotels.com is unreachable to probing
tooling and the policy lives behind that same Akamai edge.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/choice-hotels-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.