generated: '2026-06-20' method: searched probe: true source: >- https://github.com/.well-known/security.txt (RFC 9116, fetched 200) and https://bounty.github.com. GitHub runs a public bug bounty program on HackerOne. policy: - https://bounty.github.com contact: - https://hackerone.com/github acknowledgments: - https://hackerone.com/github/hacktivity bug_bounty: platform: HackerOne url: https://hackerone.com/github program_page: https://bounty.github.com preferred_languages: en security_txt_expires: '2026-08-15T21:29:55Z' evidence: - {source: well-known/github-copilot-security.txt, kind: security.txt, host: github.com} - {source: https://bounty.github.com, kind: bug-bounty-policy} - {source: https://hackerone.com/github, kind: hackerone-program} notes: >- security.txt is published org-wide at github.com and covers GitHub Copilot. The canonical Contact is the HackerOne program; Policy points at bounty.github.com (the GitHub Bug Bounty program page).