generated: '2026-07-28' method: searched probe: true notes: >- Amex GBT runs a named, public vulnerability disclosure programme. It is published as web pages rather than as an RFC 9116 security.txt, and every page is behind the same Cloudflare bot gate that blocks the rest of the estate - so the URLs below returned 403 to automated clients and their content was confirmed from indexed page content rather than from a 200. DNS resolution independently confirms the disclosure host is a real, dedicated Zendesk instance (amexgbt.responsibledisclosure.com -> amexgbtrd.zendesk.com), which is not something that exists by accident. The 0-working/probe-security-programs.py probe returned "vdp=none" because it requires keyword-bearing 200 bodies; that is a probe limitation against Cloudflare, not evidence of absence, and this file supersedes it. policy: - https://amexgbt.responsibledisclosure.com/hc/en-us - https://www.amexglobalbusinesstravel.com/bugcrowd/ contact: - amexgbt@responsibledisclosure.com programs: - name: Amex GBT Responsible Disclosure url: https://amexgbt.responsibledisclosure.com/hc/en-us platform: responsibledisclosure.com (Synack) type: vulnerability-disclosure-program contact: amexgbt@responsibledisclosure.com commitments: - Acknowledgement of receipt within 48 business hours of submission. - >- Safe harbour - "GBT will not take legal action against, or suspend or terminate the accounts of, researchers who discover and report security vulnerabilities in accordance with this Responsible Disclosure Policy." probe: {status: 403, note: Cloudflare/Zendesk gate to automated clients} dns: amexgbtrd.zendesk.com (216.198.53.11, 216.198.54.11) - name: AMEX - Global Business Travel Vulnerability Disclosure Program url: https://www.amexglobalbusinesstravel.com/bugcrowd/ platform: Bugcrowd type: vulnerability-disclosure-program probe: {status: 403, note: Cloudflare gate} note: >- A Bugcrowd engagement page for amexgbt-vdp is indexed but returned 404 on direct fetch, which is consistent with a private or relocated engagement. The Amex GBT-hosted /bugcrowd/ landing page is treated as the citable surface. bounty: false bounty_note: >- Both programmes are disclosure programmes; no published reward table or bounty range was found. security_txt: found: false confirmed_absent: false probes: - {url: 'https://apis.egencia.com/.well-known/security.txt', status: 403} - {url: 'https://www.egencia.com/.well-known/security.txt', status: 403} - {url: 'https://www.amexglobalbusinesstravel.com/.well-known/security.txt', status: 403} note: >- All three hosts return a Cloudflare interstitial for the path rather than an origin 404, so absence could not be confirmed. Recorded as blocked, not as missing. corroboration: note: >- The eight @egencia-scoped npm packages found in the prior enrichment round all carry the description "This is created as a POC for synack. Please do not use this" - dependency-confusion proof-of-concept placeholders published in connection with a Synack engagement. That is independent corroboration that the Synack-operated responsible disclosure programme recorded here is live and exercised, and it is why those packages are NOT client SDKs. source: packages/amex-gbt-packages.yml unrelated_programs: - name: American Express (the card issuer) HackerOne programme url: https://hackerone.com/americanexpress note: >- A different corporate entity. American Express Global Business Travel has been a separate company since 2014 and is NYSE-listed as GBTG. Deliberately NOT recorded as Amex GBT's programme. evidence: - {source: 'https://amexgbt.responsibledisclosure.com/hc/en-us', kind: disclosure-portal, status: 403, dns_confirmed: true} - {source: 'https://www.amexglobalbusinesstravel.com/bugcrowd/', kind: bug-bounty-landing-page, status: 403} related: - security/amex-gbt-domain-security.yml - well-known/amex-gbt-well-known.yml