Enterprise Mobility · Vulnerability Disclosure

Enterprise Mobility Vulnerability Disclosure

Vulnerability disclosure

Enterprise Mobility runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

TravelUnited StatesCar RentalGround TransportationMobilityCorporate TravelDistributionFleet ManagementInsurance Replacement RentalBooking
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
{"address" => "CSIRT@ehi.com", "direction" => "inbound", "kind" => "incident-notification", "note" => "Published in Section 12 of the API License Agreement as the address a LICENSEE must notify within 24 hours of a security incident. It is a duty imposed on partners, not an intake channel offered to security researchers."}

Source

Vulnerability Disclosure

enterprise-mobility-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
probe: true
source: >-
  0-working/probe-security-programs.py (no hit) plus a manual read of the
  published API License Agreement at
  https://developer.ehi.com/general/terms-of-use.html. Probed 2026-07-28.
disclosure_program: false
researcher_channel: false
bug_bounty: false
security_txt: false
note: >-
  Enterprise Mobility publishes no vulnerability disclosure policy, no
  responsible-disclosure page, no bug bounty (no HackerOne / Bugcrowd /
  Intigriti presence found) and no /.well-known/security.txt on any host. This
  file records that as a verified negative, plus the one real security contact
  Enterprise does publish — which points INBOUND, at licensees, not outbound at
  researchers.
policy: []
contact:
  - address: CSIRT@ehi.com
    kind: incident-notification
    direction: inbound
    note: >-
      Published in Section 12 of the API License Agreement as the address a
      LICENSEE must notify within 24 hours of a security incident. It is a duty
      imposed on partners, not an intake channel offered to security researchers.
obligations_on_licensee:
  - >-
    "Licensee will immediately notify Enterprise at CSIRT@ehi.com within 24 hours
    of any known security breaches, incidents, unauthorized access to or use of
    the APIs"
  - >-
    "At Enterprise's request and, not more than annually, Licensee will perform a
    third party security audit of its systems, technologies and processes
    relating to the APIs, Enterprise Content, Portal and Application and promptly
    deliver a written report of the results of each audit to Enterprise."
evidence:
  - source: https://developer.ehi.com/general/terms-of-use.html
    kind: license-agreement
    status: 200
  - source: https://developer.ehi.com/.well-known/security.txt
    kind: security.txt
    status: 404
  - source: https://www.enterprisemobility.com/.well-known/security.txt
    kind: security.txt
    status: 404
  - source: https://www.enterprise.com/.well-known/security.txt
    kind: security.txt
    status: 404
  - source: https://api.ehi.com/.well-known/security.txt
    kind: security.txt
    status: 404
not_published:
  - Vulnerability disclosure policy
  - Safe-harbor language for researchers
  - Bug bounty program
  - security.txt
  - Trust center or certification list