generated: '2026-09-06' method: searched probe: true source: https://bugcrowd.com/engagements/dickssportinggoods note: >- DICK'S Sporting Goods runs a named, first-party Vulnerability Disclosure Program on Bugcrowd. The program page returns HTTP 200 and identifies the company in its own OpenGraph metadata — og:title "DICK'S Sporting Goods | Bugcrowd", og:description "Learn more about DICK'S Sporting Goods's Vulnerability Disclosure engagement powered by Bugcrowd, the leader in crowdsourced security solutions" — and carries the company logo at logos.bugcrowdusercontent.com. That is a disclosure surface the company operates, and it is the ONLY machine-findable security-program artifact this company publishes: /.well-known/security.txt is not served on any host (see well-known/dicks-sporting-goods-well-known.yml — the storefront answers 200 with an Angular app shell for every path, including a control path that cannot exist). program_type: vulnerability-disclosure paid_bounty: false policy: - https://bugcrowd.com/engagements/dickssportinggoods contact: [] security_txt: false evidence: - source: https://bugcrowd.com/engagements/dickssportinggoods kind: bug-bounty-platform platform: bugcrowd http_status: 200 fetched: '2026-09-06' signals: - 'og:title: DICK''S Sporting Goods | Bugcrowd' - 'og:description: Learn more about DICK''S Sporting Goods''s Vulnerability Disclosure engagement powered by Bugcrowd' - 'title: Vulnerability Disclosure: DICK''S Sporting Goods - Bugcrowd' - source: https://bugcrowd.com/dickssportinggoods kind: bug-bounty-platform platform: bugcrowd http_status: 200 fetched: '2026-09-06' note: Alias of the engagement URL above; serves the identical page. - source: https://hackerone.com/dicks kind: bug-bounty-platform platform: hackerone http_status: 200 fetched: '2026-09-06' note: >- A HackerOne page exists at this handle and is indexed as "Dick's Sporting Goods | Vulnerability Disclosure Policy", but the served body is a 2.3KB JavaScript app shell with no company-identifying content, so it is recorded as a lead rather than as confirmed first-party evidence. Bugcrowd is the surface that self-identifies. - source: https://www.dickssportinggoods.com/.well-known/security.txt kind: security.txt http_status: 200 fetched: '2026-09-06' result: miss note: >- Soft 404 — 2691 bytes of Angular app shell, not RFC 9116 text. The same shell is returned for a negative-control path, so the 200 is meaningless. gaps: - >- No /.well-known/security.txt on any host, so the disclosure program is undiscoverable by the RFC 9116 mechanism a scanner or an agent would use. Bugcrowd hosts the policy; the company's own domain does not point at it. - >- No security contact email published on a company-controlled surface.