generated: '2026-08-04' method: searched probe: true source: https://www.engine.com/responsible-disclosure summary: >- Engine publishes a formal Responsible Disclosure Policy covering engine.com and all subdomains, the Engine iOS and Android apps, publicly accessible APIs, and the web-based customer and partner portals. It is explicitly NOT a bug bounty — no monetary compensation is offered, though Engine reserves discretion to reward confirmed high-impact findings. Safe harbor is granted to good-faith researchers who comply with the policy terms. No RFC 9116 /.well-known/security.txt is published on any Engine host. policy: - https://www.engine.com/responsible-disclosure contact: - security@engine.com contact_evidence: >- security@engine.com is published as the iodef reporting address in Engine's DNS CAA record for engine.com (0 iodef "mailto:security@engine.com"), verified by live dig. bug_bounty: program: false note: 'Policy states: "This Policy is not a bug bounty program; no monetary compensation is offered."' platforms_checked: [HackerOne, Bugcrowd, Intigriti] platforms_found: [] safe_harbor: true acknowledgement_sla: five business days scope: in_scope: - engine.com and all subdomains (e.g. app.engine.com, api.engine.com) - Engine mobile applications (iOS and Android) - Publicly accessible APIs - Web-based customer and partner portals out_of_scope: - Payment processing systems and Engine X charge card infrastructure - Third-party systems (banking partners, travel suppliers) - Internal corporate IT systems - Physical security assets reporting_requirements: - affected asset - vulnerability type - reproduction steps - proof of concept - impact assessment - reporter contact information security_txt: published: false paths_probed: - {url: 'https://engine.com/.well-known/security.txt', status: 404} - {url: 'https://omni.engine.com/.well-known/security.txt', status: 404} - {url: 'https://hotelengine.com/.well-known/security.txt', status: 404} evidence: - {source: 'https://www.engine.com/responsible-disclosure', http_status: 200, kind: disclosure-policy, fetched: '2026-08-04'} - {source: 'dig CAA engine.com', kind: dns-caa-iodef, value: 'mailto:security@engine.com', fetched: '2026-08-04'} gaps: - No /.well-known/security.txt (RFC 9116) on any host — the machine-readable pointer to the policy that already exists.