Groupon · Vulnerability Disclosure

Groupon Vulnerability Disclosure

Vulnerability disclosure

Groupon runs a public Vulnerability Disclosure Policy on HackerOne under the team handle "groupon". Confirmed 2026-09-04 by resolving the team through the HackerOne public GraphQL endpoint, which returned {"handle":"groupon","name": "Groupon","url":"https://hackerone.com/groupon"}, and by fetching the program page (HTTP 200; the page is a JS application, so its body is not machine-readable and the reward/scope detail below is left unrecorded rather than guessed). Groupon publishes NO /.well-known/security.txt on any host in this record — the HackerOne program is the only disclosure channel found.

Groupon runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Fortune 1000Local CommerceMarketplaceE-CommerceDealsBookingsReservationsTravelRetail
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
https://hackerone.com/groupon

Source

Vulnerability Disclosure

groupon-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-04'
method: searched
probe: true
source: https://hackerone.com/groupon
description: >-
  Groupon runs a public Vulnerability Disclosure Policy on HackerOne under the
  team handle "groupon". Confirmed 2026-09-04 by resolving the team through the
  HackerOne public GraphQL endpoint, which returned {"handle":"groupon","name":
  "Groupon","url":"https://hackerone.com/groupon"}, and by fetching the program
  page (HTTP 200; the page is a JS application, so its body is not machine-readable
  and the reward/scope detail below is left unrecorded rather than guessed).
  Groupon publishes NO /.well-known/security.txt on any host in this record — the
  HackerOne program is the only disclosure channel found.
policy:
  - https://hackerone.com/groupon
contact:
  - https://hackerone.com/groupon
platform: hackerone
handle: groupon
program_type: vulnerability-disclosure
bounty: unknown
evidence:
  - source: https://hackerone.com/graphql
    kind: HackerOne public GraphQL team lookup (handle=groupon)
    result: 'team resolved: name "Groupon", url https://hackerone.com/groupon'
    fetched: '2026-09-04'
  - source: https://hackerone.com/groupon
    kind: program page fetch
    http_status: 200
    fetched: '2026-09-04'
    note: JS-rendered; body carries the strings "vulnerability disclosure", "bug bounty", "policy".
  - source: https://www.groupon.com/.well-known/security.txt
    kind: negative probe
    http_status: 404
    fetched: '2026-09-04'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/groupon-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.