generated: '2026-09-17' method: searched source: https://hackerone.com/doordash provider: doordash description: >- DoorDash runs a public bug bounty program on HackerOne. What it does NOT publish is a security.txt: the RFC 9116 probe returned 404 on the API host and the docs host, and 403 behind Cloudflare's bot interstitial on www.doordash.com, so there is no machine-readable pointer from any DoorDash domain to the program - a researcher or an agent has to already know to look on HackerOne. program: published: true type: bug-bounty platform: HackerOne url: https://hackerone.com/doordash name: DoorDash Bug Bounty Program probed: '2026-09-17' http_status: 200 evidence: >- og:title "DoorDash - Bug Bounty Program | HackerOne" and og:url https://hackerone.com/doordash served in the page head. The program's scope table, bounty ranges, response targets and safe-harbor language are rendered client-side and could not be read anonymously, so nothing about them is asserted here. summary_quoted: >- "The DoorDash Bug Bounty Program enlists the help of the hacker community at HackerOne to make DoorDash more secure." security_txt: published: false probes: - url: https://openapi.doordash.com/.well-known/security.txt status: 404 - url: https://developer.doordash.com/.well-known/security.txt status: 404 note: 302 into /en-US/, which returns the Docusaurus 404 HTML shell. - url: https://www.doordash.com/.well-known/security.txt status: 403 note: Cloudflare bot interstitial; unresolvable anonymously rather than proven absent. disclosure_policy: page_published: false note: >- No vulnerability-disclosure or responsible-disclosure page was found on doordash.com or developer.doordash.com. The policy of record is the HackerOne program policy. contact: channel: HackerOne url: https://hackerone.com/doordash gaps: - >- No /.well-known/security.txt on any DoorDash host, so the program is discoverable only by searching rather than by probing the domain.