generated: '2026-08-12' method: searched probe: true source: https://help.doit.com/docs/vendor-information/bug-bounty-program program_name: Vulnerability Reward Program program_type: self-hosted bug bounty / responsible disclosure platform: null platform_note: DoiT runs the program itself. It is not listed on HackerOne, Bugcrowd or Intigriti, and reports go to a DoiT mailbox rather than a platform intake. policy: - https://help.doit.com/docs/vendor-information/bug-bounty-program contact: - mailto:vulnerability-report@doit.com scope: DoiT-owned web properties terms: disclosure: Participants agree not to discuss or disclose ongoing work or vulnerabilities with parties outside the program without explicit DoiT consent; violation is immediate disqualification. impact_bar: Reports must demonstrate a real security risk with tangible business impact; theoretical risks requiring highly specific low-likelihood conditions are deprioritised and reports without measurable business impact are ineligible. test_accounts: Not provided. security_txt: served: false note: No /.well-known/security.txt on www.doit.com, api.doit.com, help.doit.com or mcp.doit.com (all 404 on 2026-08-12). The program is discoverable only through the help centre and the Conveyor trust centre, not through the RFC 9116 machine-readable path. related: security_policy: https://help.doit.com/docs/vendor-information/security-and-data-access-policy trust_center: https://trust.doit.com/ penetration_testing: true evidence: - source: https://help.doit.com/docs/vendor-information/bug-bounty-program kind: disclosure page http_status: 200 fetched: '2026-08-12' - source: https://trust.doit.com/ kind: trust center trust_indicator bug_bounty_resp_disclosure http_status: 200 fetched: '2026-08-12' detail: report_vulnerability_url = mailto:vulnerability-report@doit.com - source: https://www.doit.com/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-08-12'