Choice Hotels · Vulnerability Disclosure

Choice Hotels Vulnerability Disclosure

Vulnerability disclosure

Choice Hotels runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

TravelUnited StatesHospitalityHotelsBookingReservationsDistributionFranchisingLoyalty
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
responsibledisclosure@choicehotels.com

Source

Vulnerability Disclosure

choice-hotels-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
source: https://www.choicehotels.com/legal/responsible-disclosure
probe: true
name: Choice Hotels International Responsible Disclosure / Vulnerability Disclosure
  Policy
policy:
- https://www.choicehotels.com/legal/responsible-disclosure
contact:
- responsibledisclosure@choicehotels.com
contact_channel: email
bug_bounty:
  offered: false
  verbatim: Please note, Choice Hotels International does not currently offer a "bug
    bounty" program; thus, we extend no offer of compensation/reward or public recognition
    for submittal of potential vulnerabilities.
  platform: null
safe_harbor:
  offered: true
  verbatim: We will not pursue legal action, nor initiate a complaint to law enforcement,
    against the finder/researcher operating in good faith. However, Choice Hotels International
    reserves all legal rights in the event of non-compliance to the Guidelines for
    Operating in Good Faith follow included in the Policy.
scope:
  in_scope_statement: any product, system, or asset belonging to us
  out_of_scope:
  - Social Engineering, Such as Attempts to Steal Cookies, Fake LogIn Pages to Collect
    Credentials, and Phishing
  - Resource Exhaustion Attacks
  - Physical Testing
  - Denial of Service Attacks
response:
  acknowledgement_sla: five business days
  verbatim: When a report is received by the Information Security Team, an acknowledgement
    will be sent in reply to the sender within five business days. A follow-on request
    for further information may be sent as needed. After validation/verification of
    a vulnerability, a follow-up reply will be sent to the sender.
  disclosure_timeframe: No fixed embargo window is published. Choice states it "will
    not negotiate in response to a threat" and asks researchers to "allow us a reasonable
    amount of time for both the validation/verification and the resolution of the vulnerability
    before taking action to make it public."
  third_party_notification: Reporting of vulnerability information to other third parties/vendors
    will be determined at the discretion of Choice Hotels International.
submission_format: A detailed description of the vulnerability — tools utilized, target,
  processes, and results — with pertinent artifacts attached. Proposed remediation
  is welcomed but not required.
good_faith_guidelines:
- Be respectful of existing applications; avoid privacy violations, destruction of
  data, and interruption or degradation of services (including denial of service)
- Do not access or modify Choice data or stakeholder data
- Contact Choice immediately if stakeholder data is encountered; do not view, alter,
  destroy, save, share, store, transfer or otherwise compromise it, and purge any
  local information upon reporting
- Stop all activity and contact Choice immediately if personal information (names,
  addresses, email addresses, loyalty account numbers, unique identifiers, credit
  card numbers) is encountered
- Do not generate fraudulent financial transactions
- Do not violate federal, state or international laws or regulations in any jurisdiction
  where assets/data/systems reside, data traffic is routed, research is conducted,
  or data subjects reside
- Share the security and/or privacy issue with Choice
security_txt:
  published: false
  note: No RFC 9116 /.well-known/security.txt is served on any Choice Hotels host.
    See well-known/choice-hotels-well-known.yml for the full probe table. The policy
    is published as an HTML legal page only, so automated discovery of the disclosure
    channel is not possible.
evidence:
- source: https://www.choicehotels.com/legal/responsible-disclosure
  kind: disclosure-policy-page
  status: 200
  note: Live page is unreachable to non-browser tooling — the Akamai edge terminates
    HTTP/2 with INTERNAL_ERROR for automated clients (recorded HTTP 000). Content
    verified against the Internet Archive capture below, which returns the same page
    under the canonical URL.
- source: http://web.archive.org/web/20260709002042/https://www.choicehotels.com/legal/responsible-disclosure
  kind: archive-capture
  status: 200
  captured: '2026-07-09'
notes: |
  This is the first genuinely public, security-relevant program surface found on any
  Choice Hotels property. It is a policy-and-mailbox VDP: no bug bounty, no HackerOne
  / Bugcrowd / Intigriti program, no security.txt, no PGP key, and no published
  remediation SLA — only a five-business-day acknowledgement commitment. It does not
  change the provider's API posture (still no public API, no developer portal, no
  machine-readable contract) but it is a real, verifiable commitment that the round-1
  review did not surface, because www.choicehotels.com is unreachable to probing
  tooling and the policy lives behind that same Akamai edge.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/choice-hotels-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.