generated: '2026-07-28' method: searched source: https://www.choicehotels.com/legal/responsible-disclosure probe: true name: Choice Hotels International Responsible Disclosure / Vulnerability Disclosure Policy policy: - https://www.choicehotels.com/legal/responsible-disclosure contact: - responsibledisclosure@choicehotels.com contact_channel: email bug_bounty: offered: false verbatim: Please note, Choice Hotels International does not currently offer a "bug bounty" program; thus, we extend no offer of compensation/reward or public recognition for submittal of potential vulnerabilities. platform: null safe_harbor: offered: true verbatim: We will not pursue legal action, nor initiate a complaint to law enforcement, against the finder/researcher operating in good faith. However, Choice Hotels International reserves all legal rights in the event of non-compliance to the Guidelines for Operating in Good Faith follow included in the Policy. scope: in_scope_statement: any product, system, or asset belonging to us out_of_scope: - Social Engineering, Such as Attempts to Steal Cookies, Fake LogIn Pages to Collect Credentials, and Phishing - Resource Exhaustion Attacks - Physical Testing - Denial of Service Attacks response: acknowledgement_sla: five business days verbatim: When a report is received by the Information Security Team, an acknowledgement will be sent in reply to the sender within five business days. A follow-on request for further information may be sent as needed. After validation/verification of a vulnerability, a follow-up reply will be sent to the sender. disclosure_timeframe: No fixed embargo window is published. Choice states it "will not negotiate in response to a threat" and asks researchers to "allow us a reasonable amount of time for both the validation/verification and the resolution of the vulnerability before taking action to make it public." third_party_notification: Reporting of vulnerability information to other third parties/vendors will be determined at the discretion of Choice Hotels International. submission_format: A detailed description of the vulnerability — tools utilized, target, processes, and results — with pertinent artifacts attached. Proposed remediation is welcomed but not required. good_faith_guidelines: - Be respectful of existing applications; avoid privacy violations, destruction of data, and interruption or degradation of services (including denial of service) - Do not access or modify Choice data or stakeholder data - Contact Choice immediately if stakeholder data is encountered; do not view, alter, destroy, save, share, store, transfer or otherwise compromise it, and purge any local information upon reporting - Stop all activity and contact Choice immediately if personal information (names, addresses, email addresses, loyalty account numbers, unique identifiers, credit card numbers) is encountered - Do not generate fraudulent financial transactions - Do not violate federal, state or international laws or regulations in any jurisdiction where assets/data/systems reside, data traffic is routed, research is conducted, or data subjects reside - Share the security and/or privacy issue with Choice security_txt: published: false note: No RFC 9116 /.well-known/security.txt is served on any Choice Hotels host. See well-known/choice-hotels-well-known.yml for the full probe table. The policy is published as an HTML legal page only, so automated discovery of the disclosure channel is not possible. evidence: - source: https://www.choicehotels.com/legal/responsible-disclosure kind: disclosure-policy-page status: 200 note: Live page is unreachable to non-browser tooling — the Akamai edge terminates HTTP/2 with INTERNAL_ERROR for automated clients (recorded HTTP 000). Content verified against the Internet Archive capture below, which returns the same page under the canonical URL. - source: http://web.archive.org/web/20260709002042/https://www.choicehotels.com/legal/responsible-disclosure kind: archive-capture status: 200 captured: '2026-07-09' notes: | This is the first genuinely public, security-relevant program surface found on any Choice Hotels property. It is a policy-and-mailbox VDP: no bug bounty, no HackerOne / Bugcrowd / Intigriti program, no security.txt, no PGP key, and no published remediation SLA — only a five-business-day acknowledgement commitment. It does not change the provider's API posture (still no public API, no developer portal, no machine-readable contract) but it is a real, verifiable commitment that the round-1 review did not surface, because www.choicehotels.com is unreachable to probing tooling and the policy lives behind that same Akamai edge.