Discover · Vulnerability Disclosure

Discover Vulnerability Disclosure

Vulnerability disclosure

Discover runs a coordinated vulnerability disclosure program on Hackerone.

Credit CardsPaymentsCard NetworkTokenizationFinancial ServicesFraudFortune 500
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

discover-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-06'
method: searched
probe: true
source: https://www.discover.com/responsible-disclosure
policy:
- https://www.discover.com/responsible-disclosure
- https://www.discover.com/responsible-disclosure/scope-and-roe/
submission:
- https://hackerone.com/6fbb634b-1079-49b8-a63c-453c8b74e8b4/embedded_submissions/new
platform: HackerOne (embedded submission form on discover.com)
safe_harbor: >-
  "By responsibly submitting your findings to Discover in accordance with these guidelines,
  Discover agrees not to pursue legal action against you."
bounty: false
bounty_detail: The policy states researchers must "not request compensation for time and materials
  or vulnerabilities discovered" - recognition and coordinated disclosure, not a paid bounty.
disclosure_terms: >-
  A researcher whose report is in scope and valid "will be allowed to disclose the vulnerability
  after a fix has been issued".
in_scope:
- OWASP Top 10 vulnerability categories
- Other vulnerabilities with demonstrated impact
out_of_scope:
- Theoretical vulnerabilities
- Informational disclosure of non-sensitive data
- Low impact session management issues
- Self XSS (user defined payload)
- Denial of service testing
- Physical or social engineering
- Testing of third-party services
- Clickjacking / UI redressing
- Incomplete or missing SPF/DMARC/DKIM records
- Account/email enumeration using brute-force attacks
rules_of_engagement: https://www.discover.com/responsible-disclosure/scope-and-roe/
security_txt: null
security_txt_note: >-
  No /.well-known/security.txt on any Discover host - probed www.discover.com,
  www.discoverglobalnetwork.com, partner.discoverglobalnetwork.com, developer.discover.com,
  apis.discover.com and sandbox.apis.discover.com, all 404. Discover runs a real disclosure
  programme it does not advertise at the RFC 9116 location.
evidence:
- source: https://www.discover.com/responsible-disclosure
  kind: disclosure-policy
  status: 200
  fetched: '2026-09-06'
- source: https://www.discover.com/responsible-disclosure/scope-and-roe/
  kind: scope-and-rules-of-engagement
  status: 200
  fetched: '2026-09-06'
- source: https://hackerone.com/6fbb634b-1079-49b8-a63c-453c8b74e8b4/embedded_submissions/new
  kind: submission-endpoint
  note: linked from the policy page

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/discover-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.