Choice Hotels · Vulnerability Disclosure

Choice Hotels Vulnerability Disclosure

Vulnerability disclosure

Choice Hotels runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

TravelUnited StatesHospitalityHotelsBookingReservationsDistributionFranchisingLoyalty
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
responsibledisclosure@choicehotels.com

Source

Vulnerability Disclosure

choice-hotels-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
source: https://www.choicehotels.com/legal/responsible-disclosure
probe: true
name: Choice Hotels International Responsible Disclosure / Vulnerability Disclosure
  Policy
policy:
- https://www.choicehotels.com/legal/responsible-disclosure
contact:
- responsibledisclosure@choicehotels.com
contact_channel: email
bug_bounty:
  offered: false
  verbatim: Please note, Choice Hotels International does not currently offer a "bug
    bounty" program; thus, we extend no offer of compensation/reward or public recognition
    for submittal of potential vulnerabilities.
  platform: null
safe_harbor:
  offered: true
  verbatim: We will not pursue legal action, nor initiate a complaint to law enforcement,
    against the finder/researcher operating in good faith. However, Choice Hotels International
    reserves all legal rights in the event of non-compliance to the Guidelines for
    Operating in Good Faith follow included in the Policy.
scope:
  in_scope_statement: any product, system, or asset belonging to us
  out_of_scope:
  - Social Engineering, Such as Attempts to Steal Cookies, Fake LogIn Pages to Collect
    Credentials, and Phishing
  - Resource Exhaustion Attacks
  - Physical Testing
  - Denial of Service Attacks
response:
  acknowledgement_sla: five business days
  verbatim: When a report is received by the Information Security Team, an acknowledgement
    will be sent in reply to the sender within five business days. A follow-on request
    for further information may be sent as needed. After validation/verification of
    a vulnerability, a follow-up reply will be sent to the sender.
  disclosure_timeframe: No fixed embargo window is published. Choice states it "will
    not negotiate in response to a threat" and asks researchers to "allow us a reasonable
    amount of time for both the validation/verification and the resolution of the vulnerability
    before taking action to make it public."
  third_party_notification: Reporting of vulnerability information to other third parties/vendors
    will be determined at the discretion of Choice Hotels International.
submission_format: A detailed description of the vulnerability — tools utilized, target,
  processes, and results — with pertinent artifacts attached. Proposed remediation
  is welcomed but not required.
good_faith_guidelines:
- Be respectful of existing applications; avoid privacy violations, destruction of
  data, and interruption or degradation of services (including denial of service)
- Do not access or modify Choice data or stakeholder data
- Contact Choice immediately if stakeholder data is encountered; do not view, alter,
  destroy, save, share, store, transfer or otherwise compromise it, and purge any
  local information upon reporting
- Stop all activity and contact Choice immediately if personal information (names,
  addresses, email addresses, loyalty account numbers, unique identifiers, credit
  card numbers) is encountered
- Do not generate fraudulent financial transactions
- Do not violate federal, state or international laws or regulations in any jurisdiction
  where assets/data/systems reside, data traffic is routed, research is conducted,
  or data subjects reside
- Share the security and/or privacy issue with Choice
security_txt:
  published: false
  note: No RFC 9116 /.well-known/security.txt is served on any Choice Hotels host.
    See well-known/choice-hotels-well-known.yml for the full probe table. The policy
    is published as an HTML legal page only, so automated discovery of the disclosure
    channel is not possible.
evidence:
- source: https://www.choicehotels.com/legal/responsible-disclosure
  kind: disclosure-policy-page
  status: 200
  note: Live page is unreachable to non-browser tooling — the Akamai edge terminates
    HTTP/2 with INTERNAL_ERROR for automated clients (recorded HTTP 000). Content
    verified against the Internet Archive capture below, which returns the same page
    under the canonical URL.
- source: http://web.archive.org/web/20260709002042/https://www.choicehotels.com/legal/responsible-disclosure
  kind: archive-capture
  status: 200
  captured: '2026-07-09'
notes: |
  This is the first genuinely public, security-relevant program surface found on any
  Choice Hotels property. It is a policy-and-mailbox VDP: no bug bounty, no HackerOne
  / Bugcrowd / Intigriti program, no security.txt, no PGP key, and no published
  remediation SLA — only a five-business-day acknowledgement commitment. It does not
  change the provider's API posture (still no public API, no developer portal, no
  machine-readable contract) but it is a real, verifiable commitment that the round-1
  review did not surface, because www.choicehotels.com is unreachable to probing
  tooling and the policy lives behind that same Akamai edge.