specification: API Evangelist Vulnerability Disclosure specificationVersion: '0.1' provider: General Motors providerId: general-motors generated: '2026-09-12' method: searched source: https://hackerone.com/gm description: >- General Motors runs a public Vulnerability Disclosure Program on HackerOne. GM was the first major automaker to launch one (January 2016) and the program covers GM products and services, including its vehicles and connected-vehicle services. program: name: General Motors - Vulnerability Disclosure Program platform: HackerOne url: https://hackerone.com/gm type: vulnerability-disclosure bounty: false safe_harbor: true safe_harbor_note: >- GM states it will not pursue civil action against researchers who comply with GM and HackerOne policy, and treats conduct consistent with the GM policy terms as authorized under the Computer Fraud and Abuse Act. policy: - https://hackerone.com/gm contact: - https://hackerone.com/gm - mailto:cyber@gm.com supporting_pages: - url: https://www.gm.com/cybersecurity title: Cybersecurity Tips & Best Practices | General Motors status: 200 security_txt: published: false note: >- No /.well-known/security.txt on gm.com, www.gm.com, developer.gm.com, api.gm.com or api.onstarfleetintelligence.com — see well-known/general-motors-well-known.yml. GM runs the program but does not advertise it from an RFC 9116 file, so an automated scanner finds nothing at the standard path. evidence: - url: https://hackerone.com/gm status: 200 kind: HackerOne program page detail: >- og:title "General Motors - Vulnerability Disclosure Program | HackerOne"; a control probe of a nonsense HackerOne slug returned 404, so the 200 is a real program page and not a catch-all. - url: https://www.gm.com/cybersecurity status: 200 kind: first-party cybersecurity page maintainers: - FN: Kin Lane email: kin@apievangelist.com