specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: Algolia providerId: algolia generated: '2026-08-27' method: searched source: https://hackerone.com/algolia description: >- Algolia runs a public, paid bug bounty on HackerOne. The program is real and verified, but it is NOT discoverable the way a scanner or an agent would look for it: /.well-known/security.txt returns 404 on every Algolia host, and no vulnerability-disclosure page exists under www.algolia.com/policies/. The program is only findable by going to HackerOne directly. program: platform: HackerOne url: https://hackerone.com/algolia handle: algolia name: Algolia state: public_mode submission_state: paused offers_bounties: true minimum_bounty: USD 100 bounty_note: 'Reward depends on severity and is paid via HackerOne only.' thanks_page: https://hackerone.com/algolia/thanks verified: method: 'POST https://hackerone.com/graphql query team(handle:"algolia")' http_status: 200 fields_returned: [handle, name, state, submission_state, offers_bounties, policy] note: >- submission_state is "paused" at the time of this probe, meaning the program is publicly listed and has a published policy but is not accepting new reports at this moment. Recorded as observed rather than smoothed over. scope: in_scope: - 'Website related endpoints on www.algolia.com or dashboard.algolia.com' - 'API related endpoints on *.algolia.net or *.algolianet.com' rules: - 'DO NOT use automated scanning tools.' - 'You must be the first reporter of the vulnerability.' - 'Follow https://hackerone.com/disclosure-guidelines' - 'Do not access data of other users.' note: >- The scope list is a useful independent confirmation of Algolia''s real API hosts - *.algolia.net and *.algolianet.com are exactly the servers[] hosts in the first-party OpenAPI documents. security_txt: published: false probed: - url: https://www.algolia.com/.well-known/security.txt status: 404 - url: https://algolia.com/.well-known/security.txt status: 404 - url: https://dashboard.algolia.com/.well-known/security.txt status: 404 - url: https://www.algolia.com/security.txt status: 404 - url: https://status.algolia.com/.well-known/security.txt status: 200 note: 'HTTP 200 but the body is the status-page SPA shell, not a security.txt. A miss.' gap: >- A published HackerOne program with no security.txt is the classic discoverability gap: the program exists, is paid, and has a written policy, but nothing on any Algolia host points a researcher or an automated agent at it. One RFC 9116 file at https://www.algolia.com/.well-known/security.txt with a Policy: line pointing at https://hackerone.com/algolia would close it. other_disclosure_pages_probed: - url: https://www.algolia.com/policies/vulnerability-disclosure/ status: 404 - url: https://www.algolia.com/policies/security/ status: 404 - url: https://bugcrowd.com/algolia status: 404