Hyatt Hotels · Vulnerability Disclosure

Hyatt Hotels Vulnerability Disclosure

Vulnerability disclosure

Hyatt Hotels runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

HospitalityHotelsTravelLodgingResortsLoyaltyReservationsFortune 1000
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@hyatt.com

Source

Vulnerability Disclosure

hyatt-hotels-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-13'
method: searched
probe: true
source: https://newsroom.hyatt.com/hackerone-bug-bounty
program:
  name: Hyatt Hotels — Bug Bounty Program
  platform: HackerOne
  type: public-bug-bounty
  url: https://hackerone.com/hyatt
  launched: '2019-01-09'
  launched_as: >-
    Public, after a private invitation-only HackerOne program run through late 2018.
  announced_by: >-
    Hyatt Hotels Corporation newsroom release "Hyatt Launches Public Bug Bounty Program With
    HackerOne", quoting then-CISO Benjamin Vaughn.
  scope:
    - Hyatt.com
    - m.hyatt.com
    - world.hyatt.com
    - Hyatt mobile app (iOS)
    - Hyatt mobile app (Android)
  scope_source: https://newsroom.hyatt.com/hackerone-bug-bounty
  eligibility: >-
    Open to all ethical hackers who accept HackerOne's terms and conditions and adhere to
    its disclosure guidelines.
policy:
  - https://hackerone.com/hyatt
contact:
  - security@hyatt.com
contact_source: >-
  Published by Hyatt in DNS, not in a security.txt — the hyatt.com CAA record set carries
  `0 iodef "mailto:security@hyatt.com"` (RFC 8659 incident-reporting address), captured in
  security/hyatt-hotels-domain-security.yml.
evidence:
  - source: https://newsroom.hyatt.com/hackerone-bug-bounty
    kind: first-party press release
    http_status: 200
    note: >-
      Hyatt-operated newsroom host. Full text names the program, the platform, the in-scope
      hosts and apps, and points readers at hackerone.com/hyatt.
  - source: https://hackerone.com/hyatt
    kind: bug-bounty program page
    http_status: 200
    note: >-
      Live program page. The body is client-side rendered, so the policy detail (current
      bounty table, safe-harbour text) was not machine-readable at probe time; presence and
      ownership are confirmed by the first-party release above.
  - source: security/hyatt-hotels-domain-security.yml
    kind: CAA iodef record
    note: '0 iodef "mailto:security@hyatt.com" on hyatt.com'
not_found:
  - path: https://www.hyatt.com/.well-known/security.txt
    status: 403
    note: >-
      Hyatt serves no RFC 9116 security.txt that we could read; the customer-facing hyatt.com
      hosts answer an edge bot challenge (403, Hyatt error E6020) on every path, so this is
      recorded as unknown rather than as an absence.
  - path: https://bugcrowd.com/hyatt
    status: 404
note: >-
  Hyatt runs a real, public, first-party coordinated vulnerability disclosure program and has
  done so since January 2019 — one of the first global hospitality brands to do so. This is a
  verified hit, so a Security pointer (the type the security_disclosure check reads) and a
  VulnerabilityDisclosure pointer are both wired in apis.yml. The program covers Hyatt's
  consumer web and mobile estate; it does not imply a developer API program, and none was
  found.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hyatt-hotels-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.