generated: '2026-07-19' method: searched probe: true source: https://www.holidu.com/.well-known/security.txt contact: - mailto:security@holidu.com policy_summary: >- Holidu operates an invite-only bug bounty program through HackerOne. Researchers email a detailed report plus their HackerOne username; eligible submissions may be invited to the private program. bug_bounty: platform: HackerOne model: invite-only / private preferred_languages: en expires: '2026-12-31T23:00:00.000Z' evidence: - source: well-known/holidu-security.txt kind: security.txt (RFC 9116, live probe)