Gap · Vulnerability Disclosure

Gap Vulnerability Disclosure

Vulnerability disclosure

Gap runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Fortune 500RetailApparelE-CommerceFashionConsumer Goods
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
https://hackerone.com/gap

Source

Vulnerability Disclosure

gap-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-10'
method: searched
probe: true
source: https://hackerone.com/gap
docs: https://hackerone.com/gap
program:
  name: Gap
  platform: HackerOne
  handle: gap
  url: https://hackerone.com/gap
  status: 200
  type: vulnerability-disclosure
  ownership_check: >-
    The HackerOne team `gap` records its website as http://www.gapinc.com — the corporate
    domain of Gap Inc., the apparel retailer profiled here. Confirmed by anonymous HackerOne
    GraphQL query on 2026-09-10 (team(handle:"gap"){name,website}) which returned
    name="Gap", website="http://www.gapinc.com". This is not the unrelated "GAP" software
    or telecom brands that share the acronym.
  bounty: unknown
  bounty_note: >-
    HackerOne's anonymous GraphQL surface returned null for offers_bounties and an empty
    policy body for this team, so whether the programme pays bounties or is disclosure-only
    could not be established without an authenticated HackerOne session. Recorded as
    unknown rather than guessed.
  scope_note: >-
    The structured_scopes edge list came back empty to an anonymous caller. In-scope assets
    could not be enumerated; do not infer that gap.com or gapinc.com are in scope.
contact:
  - https://hackerone.com/gap
security_txt:
  present: false
  note: >-
    No /.well-known/security.txt is served on any Gap-controlled host. 8 hosts were probed
    on 2026-09-10 (www.gap.com, gap.com, www.gapinc.com, api.gap.com, developer.gap.com,
    oldnavy.gap.com, bananarepublic.gap.com, athleta.gap.com) and every one returned 404
    (or, for gap.com, a 301 to the www host that then 404d). See
    well-known/gap-well-known.yml for the full probe matrix. Publishing an RFC 9116
    security.txt pointing at https://hackerone.com/gap would make this existing programme
    machine-discoverable at zero cost.
evidence:
  - source: https://hackerone.com/gap
    kind: HackerOne programme page (live probe 2026-09-10, HTTP 200)
  - source: https://hackerone.com/graphql
    kind: >-
      Anonymous HackerOne GraphQL query team(handle:"gap") returned name="Gap",
      website="http://www.gapinc.com" — the ownership proof tying this programme to Gap Inc.
  - source: https://www.gap.com/.well-known/security.txt
    kind: live probe 2026-09-10, HTTP 404 — no security.txt served

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/gap-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.