Doordash · Vulnerability Disclosure
Doordash Vulnerability Disclosure
Vulnerability disclosure
DoorDash runs a public bug bounty program on HackerOne. What it does NOT publish is a security.txt: the RFC 9116 probe returned 404 on the API host and the docs host, and 403 behind Cloudflare's bot interstitial on www.doordash.com, so there is no machine-readable pointer from any DoorDash domain to the program - a researcher or an agent has to already know to look on HackerOne.
Doordash runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
DeliveryLogisticsLast Mile DeliveryOn-DemandFood DeliveryLocal CommerceMarketplaceRestaurantGroceryRetailFulfillmentWebhook
Program: Hackerone
Disclosure Policy
Security Contact
Contact
channelHackerOne
Contact
urlhttps://hackerone.com/doordash
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.