generated: '2026-09-10' method: searched probe: true source: https://hackerone.com/gap docs: https://hackerone.com/gap program: name: Gap platform: HackerOne handle: gap url: https://hackerone.com/gap status: 200 type: vulnerability-disclosure ownership_check: >- The HackerOne team `gap` records its website as http://www.gapinc.com — the corporate domain of Gap Inc., the apparel retailer profiled here. Confirmed by anonymous HackerOne GraphQL query on 2026-09-10 (team(handle:"gap"){name,website}) which returned name="Gap", website="http://www.gapinc.com". This is not the unrelated "GAP" software or telecom brands that share the acronym. bounty: unknown bounty_note: >- HackerOne's anonymous GraphQL surface returned null for offers_bounties and an empty policy body for this team, so whether the programme pays bounties or is disclosure-only could not be established without an authenticated HackerOne session. Recorded as unknown rather than guessed. scope_note: >- The structured_scopes edge list came back empty to an anonymous caller. In-scope assets could not be enumerated; do not infer that gap.com or gapinc.com are in scope. contact: - https://hackerone.com/gap security_txt: present: false note: >- No /.well-known/security.txt is served on any Gap-controlled host. 8 hosts were probed on 2026-09-10 (www.gap.com, gap.com, www.gapinc.com, api.gap.com, developer.gap.com, oldnavy.gap.com, bananarepublic.gap.com, athleta.gap.com) and every one returned 404 (or, for gap.com, a 301 to the www host that then 404d). See well-known/gap-well-known.yml for the full probe matrix. Publishing an RFC 9116 security.txt pointing at https://hackerone.com/gap would make this existing programme machine-discoverable at zero cost. evidence: - source: https://hackerone.com/gap kind: HackerOne programme page (live probe 2026-09-10, HTTP 200) - source: https://hackerone.com/graphql kind: >- Anonymous HackerOne GraphQL query team(handle:"gap") returned name="Gap", website="http://www.gapinc.com" — the ownership proof tying this programme to Gap Inc. - source: https://www.gap.com/.well-known/security.txt kind: live probe 2026-09-10, HTTP 404 — no security.txt served