generated: '2026-09-06' method: searched probe: true source: https://www.discover.com/responsible-disclosure policy: - https://www.discover.com/responsible-disclosure - https://www.discover.com/responsible-disclosure/scope-and-roe/ submission: - https://hackerone.com/6fbb634b-1079-49b8-a63c-453c8b74e8b4/embedded_submissions/new platform: HackerOne (embedded submission form on discover.com) safe_harbor: >- "By responsibly submitting your findings to Discover in accordance with these guidelines, Discover agrees not to pursue legal action against you." bounty: false bounty_detail: The policy states researchers must "not request compensation for time and materials or vulnerabilities discovered" - recognition and coordinated disclosure, not a paid bounty. disclosure_terms: >- A researcher whose report is in scope and valid "will be allowed to disclose the vulnerability after a fix has been issued". in_scope: - OWASP Top 10 vulnerability categories - Other vulnerabilities with demonstrated impact out_of_scope: - Theoretical vulnerabilities - Informational disclosure of non-sensitive data - Low impact session management issues - Self XSS (user defined payload) - Denial of service testing - Physical or social engineering - Testing of third-party services - Clickjacking / UI redressing - Incomplete or missing SPF/DMARC/DKIM records - Account/email enumeration using brute-force attacks rules_of_engagement: https://www.discover.com/responsible-disclosure/scope-and-roe/ security_txt: null security_txt_note: >- No /.well-known/security.txt on any Discover host - probed www.discover.com, www.discoverglobalnetwork.com, partner.discoverglobalnetwork.com, developer.discover.com, apis.discover.com and sandbox.apis.discover.com, all 404. Discover runs a real disclosure programme it does not advertise at the RFC 9116 location. evidence: - source: https://www.discover.com/responsible-disclosure kind: disclosure-policy status: 200 fetched: '2026-09-06' - source: https://www.discover.com/responsible-disclosure/scope-and-roe/ kind: scope-and-rules-of-engagement status: 200 fetched: '2026-09-06' - source: https://hackerone.com/6fbb634b-1079-49b8-a63c-453c8b74e8b4/embedded_submissions/new kind: submission-endpoint note: linked from the policy page