generated: '2026-09-04' method: searched probe: true source: https://hackerone.com/groupon description: >- Groupon runs a public Vulnerability Disclosure Policy on HackerOne under the team handle "groupon". Confirmed 2026-09-04 by resolving the team through the HackerOne public GraphQL endpoint, which returned {"handle":"groupon","name": "Groupon","url":"https://hackerone.com/groupon"}, and by fetching the program page (HTTP 200; the page is a JS application, so its body is not machine-readable and the reward/scope detail below is left unrecorded rather than guessed). Groupon publishes NO /.well-known/security.txt on any host in this record — the HackerOne program is the only disclosure channel found. policy: - https://hackerone.com/groupon contact: - https://hackerone.com/groupon platform: hackerone handle: groupon program_type: vulnerability-disclosure bounty: unknown evidence: - source: https://hackerone.com/graphql kind: HackerOne public GraphQL team lookup (handle=groupon) result: 'team resolved: name "Groupon", url https://hackerone.com/groupon' fetched: '2026-09-04' - source: https://hackerone.com/groupon kind: program page fetch http_status: 200 fetched: '2026-09-04' note: JS-rendered; body carries the strings "vulnerability disclosure", "bug bounty", "policy". - source: https://www.groupon.com/.well-known/security.txt kind: negative probe http_status: 404 fetched: '2026-09-04'