Engine · Vulnerability Disclosure

Hotel Engine Vulnerability Disclosure

Vulnerability disclosure

Engine runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyTravelBusiness TravelLodgingHotelsBookingTravel ManagementExpense ManagementPaymentsgRPCProtobufPartner API
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@engine.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: searched
probe: true
source: https://www.engine.com/responsible-disclosure
summary: >-
  Engine publishes a formal Responsible Disclosure Policy covering engine.com and all
  subdomains, the Engine iOS and Android apps, publicly accessible APIs, and the web-based
  customer and partner portals. It is explicitly NOT a bug bounty — no monetary compensation
  is offered, though Engine reserves discretion to reward confirmed high-impact findings.
  Safe harbor is granted to good-faith researchers who comply with the policy terms. No
  RFC 9116 /.well-known/security.txt is published on any Engine host.
policy:
  - https://www.engine.com/responsible-disclosure
contact:
  - security@engine.com
contact_evidence: >-
  security@engine.com is published as the iodef reporting address in Engine's DNS CAA record
  for engine.com (0 iodef "mailto:security@engine.com"), verified by live dig.
bug_bounty:
  program: false
  note: 'Policy states: "This Policy is not a bug bounty program; no monetary compensation is offered."'
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  platforms_found: []
safe_harbor: true
acknowledgement_sla: five business days
scope:
  in_scope:
    - engine.com and all subdomains (e.g. app.engine.com, api.engine.com)
    - Engine mobile applications (iOS and Android)
    - Publicly accessible APIs
    - Web-based customer and partner portals
  out_of_scope:
    - Payment processing systems and Engine X charge card infrastructure
    - Third-party systems (banking partners, travel suppliers)
    - Internal corporate IT systems
    - Physical security assets
reporting_requirements:
  - affected asset
  - vulnerability type
  - reproduction steps
  - proof of concept
  - impact assessment
  - reporter contact information
security_txt:
  published: false
  paths_probed:
    - {url: 'https://engine.com/.well-known/security.txt', status: 404}
    - {url: 'https://omni.engine.com/.well-known/security.txt', status: 404}
    - {url: 'https://hotelengine.com/.well-known/security.txt', status: 404}
evidence:
  - {source: 'https://www.engine.com/responsible-disclosure', http_status: 200, kind: disclosure-policy, fetched: '2026-08-04'}
  - {source: 'dig CAA engine.com', kind: dns-caa-iodef, value: 'mailto:security@engine.com', fetched: '2026-08-04'}
gaps:
  - No /.well-known/security.txt (RFC 9116) on any host — the machine-readable pointer to the policy that already exists.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hotel-engine-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.