Engine · Vulnerability Disclosure

Hotel Engine Vulnerability Disclosure

Vulnerability disclosure

Engine runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyTravelBusiness TravelLodgingHotelsBookingTravel ManagementExpense ManagementPaymentsgRPCProtobufPartner API
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@engine.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: searched
probe: true
source: https://www.engine.com/responsible-disclosure
summary: >-
  Engine publishes a formal Responsible Disclosure Policy covering engine.com and all
  subdomains, the Engine iOS and Android apps, publicly accessible APIs, and the web-based
  customer and partner portals. It is explicitly NOT a bug bounty — no monetary compensation
  is offered, though Engine reserves discretion to reward confirmed high-impact findings.
  Safe harbor is granted to good-faith researchers who comply with the policy terms. No
  RFC 9116 /.well-known/security.txt is published on any Engine host.
policy:
  - https://www.engine.com/responsible-disclosure
contact:
  - security@engine.com
contact_evidence: >-
  security@engine.com is published as the iodef reporting address in Engine's DNS CAA record
  for engine.com (0 iodef "mailto:security@engine.com"), verified by live dig.
bug_bounty:
  program: false
  note: 'Policy states: "This Policy is not a bug bounty program; no monetary compensation is offered."'
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  platforms_found: []
safe_harbor: true
acknowledgement_sla: five business days
scope:
  in_scope:
    - engine.com and all subdomains (e.g. app.engine.com, api.engine.com)
    - Engine mobile applications (iOS and Android)
    - Publicly accessible APIs
    - Web-based customer and partner portals
  out_of_scope:
    - Payment processing systems and Engine X charge card infrastructure
    - Third-party systems (banking partners, travel suppliers)
    - Internal corporate IT systems
    - Physical security assets
reporting_requirements:
  - affected asset
  - vulnerability type
  - reproduction steps
  - proof of concept
  - impact assessment
  - reporter contact information
security_txt:
  published: false
  paths_probed:
    - {url: 'https://engine.com/.well-known/security.txt', status: 404}
    - {url: 'https://omni.engine.com/.well-known/security.txt', status: 404}
    - {url: 'https://hotelengine.com/.well-known/security.txt', status: 404}
evidence:
  - {source: 'https://www.engine.com/responsible-disclosure', http_status: 200, kind: disclosure-policy, fetched: '2026-08-04'}
  - {source: 'dig CAA engine.com', kind: dns-caa-iodef, value: 'mailto:security@engine.com', fetched: '2026-08-04'}
gaps:
  - No /.well-known/security.txt (RFC 9116) on any host — the machine-readable pointer to the policy that already exists.