Groupon Vulnerability Disclosure
Groupon runs a public Vulnerability Disclosure Policy on HackerOne under the team handle "groupon". Confirmed 2026-09-04 by resolving the team through the HackerOne public GraphQL endpoint, which returned {"handle":"groupon","name": "Groupon","url":"https://hackerone.com/groupon"}, and by fetching the program page (HTTP 200; the page is a JS application, so its body is not machine-readable and the reward/scope detail below is left unrecorded rather than guessed). Groupon publishes NO /.well-known/security.txt on any host in this record — the HackerOne program is the only disclosure channel found.
Groupon runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.