generated: '2026-08-27' method: searched source: https://bugcrowd.com/engagements/onetrust provider: OneTrust providerId: onetrust summary: >- OneTrust runs a public crowdsourced bug bounty program on Bugcrowd. It does NOT serve an RFC 9116 /.well-known/security.txt on any of its hosts, and it publishes no vulnerability-disclosure page on www.onetrust.com — every candidate path returns the site's soft-404 template. programs: - name: OneTrust Bug Bounty platform: bugcrowd url: https://bugcrowd.com/engagements/onetrust type: bug-bounty status: published evidence: fetched: '2026-08-27' url: https://bugcrowd.com/engagements/onetrust http_status: 200 page_title: 'Bug Bounty: OneTrust - Bugcrowd' security_txt: published: false probes: - url: https://www.onetrust.com/.well-known/security.txt status: 403 note: Edge returned a bot-challenge 403 rather than a document. - url: https://developer.onetrust.com/.well-known/security.txt status: 200 note: 200 but the body is the ReadMe single-page-app shell, not an RFC 9116 document. Treated as a miss. - url: https://app.onetrust.com/.well-known/security.txt status: 401 - url: https://my.onetrust.com/.well-known/security.txt status: 401 negative_probes: - url: https://www.onetrust.com/vulnerability-disclosure/ status: 200 verdict: soft-404 detail: Redirects to https://www.onetrust.com/error-pages/404/ - url: https://www.onetrust.com/security/responsible-disclosure/ status: 200 verdict: soft-404 detail: Redirects to https://www.onetrust.com/error-pages/404/ - url: https://hackerone.com/onetrust status: 200 verdict: not-a-program detail: A HackerOne user profile named "onetrust", not a OneTrust-run program. maintainers: - FN: Kin Lane email: kin@apievangelist.com