Choice Hotels · Vulnerability Disclosure
Choice Hotels Vulnerability Disclosure
Vulnerability disclosure
Choice Hotels runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
TravelUnited StatesHospitalityHotelsBookingReservationsDistributionFranchisingLoyalty
Program: Hackerone
Disclosure Policy
Security Contact
Contact
responsibledisclosure@choicehotels.com
Source
Vulnerability Disclosure
generated: '2026-07-28'
method: searched
source: https://www.choicehotels.com/legal/responsible-disclosure
probe: true
name: Choice Hotels International Responsible Disclosure / Vulnerability Disclosure
Policy
policy:
- https://www.choicehotels.com/legal/responsible-disclosure
contact:
- responsibledisclosure@choicehotels.com
contact_channel: email
bug_bounty:
offered: false
verbatim: Please note, Choice Hotels International does not currently offer a "bug
bounty" program; thus, we extend no offer of compensation/reward or public recognition
for submittal of potential vulnerabilities.
platform: null
safe_harbor:
offered: true
verbatim: We will not pursue legal action, nor initiate a complaint to law enforcement,
against the finder/researcher operating in good faith. However, Choice Hotels International
reserves all legal rights in the event of non-compliance to the Guidelines for
Operating in Good Faith follow included in the Policy.
scope:
in_scope_statement: any product, system, or asset belonging to us
out_of_scope:
- Social Engineering, Such as Attempts to Steal Cookies, Fake LogIn Pages to Collect
Credentials, and Phishing
- Resource Exhaustion Attacks
- Physical Testing
- Denial of Service Attacks
response:
acknowledgement_sla: five business days
verbatim: When a report is received by the Information Security Team, an acknowledgement
will be sent in reply to the sender within five business days. A follow-on request
for further information may be sent as needed. After validation/verification of
a vulnerability, a follow-up reply will be sent to the sender.
disclosure_timeframe: No fixed embargo window is published. Choice states it "will
not negotiate in response to a threat" and asks researchers to "allow us a reasonable
amount of time for both the validation/verification and the resolution of the vulnerability
before taking action to make it public."
third_party_notification: Reporting of vulnerability information to other third parties/vendors
will be determined at the discretion of Choice Hotels International.
submission_format: A detailed description of the vulnerability — tools utilized, target,
processes, and results — with pertinent artifacts attached. Proposed remediation
is welcomed but not required.
good_faith_guidelines:
- Be respectful of existing applications; avoid privacy violations, destruction of
data, and interruption or degradation of services (including denial of service)
- Do not access or modify Choice data or stakeholder data
- Contact Choice immediately if stakeholder data is encountered; do not view, alter,
destroy, save, share, store, transfer or otherwise compromise it, and purge any
local information upon reporting
- Stop all activity and contact Choice immediately if personal information (names,
addresses, email addresses, loyalty account numbers, unique identifiers, credit
card numbers) is encountered
- Do not generate fraudulent financial transactions
- Do not violate federal, state or international laws or regulations in any jurisdiction
where assets/data/systems reside, data traffic is routed, research is conducted,
or data subjects reside
- Share the security and/or privacy issue with Choice
security_txt:
published: false
note: No RFC 9116 /.well-known/security.txt is served on any Choice Hotels host.
See well-known/choice-hotels-well-known.yml for the full probe table. The policy
is published as an HTML legal page only, so automated discovery of the disclosure
channel is not possible.
evidence:
- source: https://www.choicehotels.com/legal/responsible-disclosure
kind: disclosure-policy-page
status: 200
note: Live page is unreachable to non-browser tooling — the Akamai edge terminates
HTTP/2 with INTERNAL_ERROR for automated clients (recorded HTTP 000). Content
verified against the Internet Archive capture below, which returns the same page
under the canonical URL.
- source: http://web.archive.org/web/20260709002042/https://www.choicehotels.com/legal/responsible-disclosure
kind: archive-capture
status: 200
captured: '2026-07-09'
notes: |
This is the first genuinely public, security-relevant program surface found on any
Choice Hotels property. It is a policy-and-mailbox VDP: no bug bounty, no HackerOne
/ Bugcrowd / Intigriti program, no security.txt, no PGP key, and no published
remediation SLA — only a five-business-day acknowledgement commitment. It does not
change the provider's API posture (still no public API, no developer portal, no
machine-readable contract) but it is a real, verifiable commitment that the round-1
review did not surface, because www.choicehotels.com is unreachable to probing
tooling and the policy lives behind that same Akamai edge.