generated: '2026-07-28' method: searched probe: true source: https://www.jetblue.com/legal/vulnerability-disclosure-policy program: JetBlue Vulnerability Disclosure Program platform: HackerOne policy: - https://www.jetblue.com/legal/vulnerability-disclosure-policy - https://hackerone.com/jetblue contact: - https://hackerone.com/jetblue security_txt: false security_txt_note: >- No RFC 9116 /.well-known/security.txt is served on www.jetblue.com, api.jetblue.com or accounts.jetblue.com — the program exists but is not machine-discoverable. anonymous_reports_accepted: true bug_bounty: unknown safe_harbor: >- "If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, and will work with you to understand and resolve the issue quickly." scope: in_scope: - www.jetblue.com - book.jetblue.com - checkin.jetblue.com - mobile.jetblue.com - movil.jetblue.com - api.jetblue.com - accounts.jetblue.com - help.jetblue.com - azrest.jetblue.com - magnolia.jetblue.com - experience.jetblue.com out_of_scope: - Any other subdomain of jetblue.com - All business partner applications and connected services prohibited_tests: - Network denial of service (DoS / DDoS) - Physical security compromises - Social engineering - Spamming and phishing stop_and_report_if_encountered: - Personally identifiable information - Financial information (credit card or bank account numbers) - Proprietary information or trade secrets - Any other data not intentionally shared publicly disclosure: coordinated: true policy: >- JetBlue asks researchers not to share a report publicly before a patch is available, may coordinate a simultaneous advisory, permits self-disclosure after checking with JetBlue, and will never publish information about the researcher without permission. evidence: - source: https://www.jetblue.com/legal/vulnerability-disclosure-policy kind: vulnerability-disclosure-policy status: 200 - source: https://hackerone.com/jetblue kind: bug-bounty-platform-program status: 200 note: 'Page title: "JetBlue - Vulnerability Disclosure Program | HackerOne".' - source: https://legacycms.jetblue.com/public/.rest/jetblue/v4/page/home/legal/vulnerability-disclosure-policy kind: cms-content-endpoint status: 200 note: Used only to read the policy copy the JS-rendered page hides.