generated: '2026-08-10' method: searched source: https://www.blackstone.com/responsible-vulnerability-disclosure/ provider: Blackstone providerId: blackstone description: >- Blackstone runs a published Responsible Vulnerability Disclosure programme covering applications and systems on Blackstone-owned domains. Reports go to the Blackstone cybersecurity team by encrypted email; the team acknowledges properly submitted reports within five business days. It is a disclosure programme, not a bug bounty — Blackstone states it does not offer rewards or compensation. program: published: true type: vulnerability-disclosure-policy bug_bounty: false rewards: false platform: none url: https://www.blackstone.com/responsible-vulnerability-disclosure/ scope: Applications and systems under a Blackstone-owned domain submission_channel: email encryption_required: true acknowledgement_sla: 5 business days contact_email: null contact_email_note: >- The programme page publishes a cybersecurity-team address, but the address was masked in every index snippet available to this pass and the page itself could not be fetched directly (see x-evidence). Not recorded rather than guessed. safe_harbor: unknown security_txt: served: false note: >- No RFC 9116 security.txt is served on any Blackstone host — the policy exists only as an HTML page. Publishing /.well-known/security.txt with a Policy and Contact line pointing at this same page would make the programme machine-discoverable at zero policy cost. This is the provider's to fix. x-evidence: - url: https://www.blackstone.com/responsible-vulnerability-disclosure/ http_status: 403 fetched: '2026-08-10' note: >- Direct fetch blocked. www.blackstone.com returns 403 with `cf-mitigated: challenge` for every non-browser client, including full browser header sets and archive proxies. The policy content recorded above was read from a public search index that had crawled the page, not from our own fetch. Confidence in the programme's existence: high (the URL is a live Blackstone-owned path with indexed policy text). Confidence in the exact field values: medium. - url: https://www.blackstone.com/.well-known/security.txt http_status: 403 fetched: '2026-08-10' - url: https://login.bx.com/.well-known/security.txt http_status: 405 fetched: '2026-08-10' - url: https://ir.blackstone.com/.well-known/security.txt http_status: 200 fetched: '2026-08-10' note: Soft 200 — 11-byte "Invalid key" body, not a security.txt. confidence: medium maintainers: - FN: Kin Lane email: kin@apievangelist.com