generated: '2026-09-13' method: searched probe: true source: https://newsroom.hyatt.com/hackerone-bug-bounty program: name: Hyatt Hotels — Bug Bounty Program platform: HackerOne type: public-bug-bounty url: https://hackerone.com/hyatt launched: '2019-01-09' launched_as: >- Public, after a private invitation-only HackerOne program run through late 2018. announced_by: >- Hyatt Hotels Corporation newsroom release "Hyatt Launches Public Bug Bounty Program With HackerOne", quoting then-CISO Benjamin Vaughn. scope: - Hyatt.com - m.hyatt.com - world.hyatt.com - Hyatt mobile app (iOS) - Hyatt mobile app (Android) scope_source: https://newsroom.hyatt.com/hackerone-bug-bounty eligibility: >- Open to all ethical hackers who accept HackerOne's terms and conditions and adhere to its disclosure guidelines. policy: - https://hackerone.com/hyatt contact: - security@hyatt.com contact_source: >- Published by Hyatt in DNS, not in a security.txt — the hyatt.com CAA record set carries `0 iodef "mailto:security@hyatt.com"` (RFC 8659 incident-reporting address), captured in security/hyatt-hotels-domain-security.yml. evidence: - source: https://newsroom.hyatt.com/hackerone-bug-bounty kind: first-party press release http_status: 200 note: >- Hyatt-operated newsroom host. Full text names the program, the platform, the in-scope hosts and apps, and points readers at hackerone.com/hyatt. - source: https://hackerone.com/hyatt kind: bug-bounty program page http_status: 200 note: >- Live program page. The body is client-side rendered, so the policy detail (current bounty table, safe-harbour text) was not machine-readable at probe time; presence and ownership are confirmed by the first-party release above. - source: security/hyatt-hotels-domain-security.yml kind: CAA iodef record note: '0 iodef "mailto:security@hyatt.com" on hyatt.com' not_found: - path: https://www.hyatt.com/.well-known/security.txt status: 403 note: >- Hyatt serves no RFC 9116 security.txt that we could read; the customer-facing hyatt.com hosts answer an edge bot challenge (403, Hyatt error E6020) on every path, so this is recorded as unknown rather than as an absence. - path: https://bugcrowd.com/hyatt status: 404 note: >- Hyatt runs a real, public, first-party coordinated vulnerability disclosure program and has done so since January 2019 — one of the first global hospitality brands to do so. This is a verified hit, so a Security pointer (the type the security_disclosure check reads) and a VulnerabilityDisclosure pointer are both wired in apis.yml. The program covers Hyatt's consumer web and mobile estate; it does not imply a developer API program, and none was found.