Hyatt Hotels · Vulnerability Disclosure
Hyatt Hotels Vulnerability Disclosure
Vulnerability disclosure
Hyatt Hotels runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
HospitalityHotelsTravelLodgingResortsLoyaltyReservationsFortune 1000
Program: Hackerone
Disclosure Policy
Security Contact
Contact
security@hyatt.com
Source
Vulnerability Disclosure
generated: '2026-09-13'
method: searched
probe: true
source: https://newsroom.hyatt.com/hackerone-bug-bounty
program:
name: Hyatt Hotels — Bug Bounty Program
platform: HackerOne
type: public-bug-bounty
url: https://hackerone.com/hyatt
launched: '2019-01-09'
launched_as: >-
Public, after a private invitation-only HackerOne program run through late 2018.
announced_by: >-
Hyatt Hotels Corporation newsroom release "Hyatt Launches Public Bug Bounty Program With
HackerOne", quoting then-CISO Benjamin Vaughn.
scope:
- Hyatt.com
- m.hyatt.com
- world.hyatt.com
- Hyatt mobile app (iOS)
- Hyatt mobile app (Android)
scope_source: https://newsroom.hyatt.com/hackerone-bug-bounty
eligibility: >-
Open to all ethical hackers who accept HackerOne's terms and conditions and adhere to
its disclosure guidelines.
policy:
- https://hackerone.com/hyatt
contact:
- security@hyatt.com
contact_source: >-
Published by Hyatt in DNS, not in a security.txt — the hyatt.com CAA record set carries
`0 iodef "mailto:security@hyatt.com"` (RFC 8659 incident-reporting address), captured in
security/hyatt-hotels-domain-security.yml.
evidence:
- source: https://newsroom.hyatt.com/hackerone-bug-bounty
kind: first-party press release
http_status: 200
note: >-
Hyatt-operated newsroom host. Full text names the program, the platform, the in-scope
hosts and apps, and points readers at hackerone.com/hyatt.
- source: https://hackerone.com/hyatt
kind: bug-bounty program page
http_status: 200
note: >-
Live program page. The body is client-side rendered, so the policy detail (current
bounty table, safe-harbour text) was not machine-readable at probe time; presence and
ownership are confirmed by the first-party release above.
- source: security/hyatt-hotels-domain-security.yml
kind: CAA iodef record
note: '0 iodef "mailto:security@hyatt.com" on hyatt.com'
not_found:
- path: https://www.hyatt.com/.well-known/security.txt
status: 403
note: >-
Hyatt serves no RFC 9116 security.txt that we could read; the customer-facing hyatt.com
hosts answer an edge bot challenge (403, Hyatt error E6020) on every path, so this is
recorded as unknown rather than as an absence.
- path: https://bugcrowd.com/hyatt
status: 404
note: >-
Hyatt runs a real, public, first-party coordinated vulnerability disclosure program and has
done so since January 2019 — one of the first global hospitality brands to do so. This is a
verified hit, so a Security pointer (the type the security_disclosure check reads) and a
VulnerabilityDisclosure pointer are both wired in apis.yml. The program covers Hyatt's
consumer web and mobile estate; it does not imply a developer API program, and none was
found.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hyatt-hotels-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.