generated: '2026-08-13' method: searched probe: true source: https://support.tiktok.com/en/safety-hc/reporting-security-vulnerabilities/reporting-the-security-vulnerabilities policy: - https://support.tiktok.com/en/safety-hc/reporting-security-vulnerabilities/reporting-the-security-vulnerabilities - https://hackerone.com/tiktok bug_bounty: platform: HackerOne url: https://hackerone.com/tiktok public: true http_status: 200 disclosure_model: coordinated contact: [] security_txt: false security_txt_note: >- TikTok serves no RFC 9116 security.txt. /.well-known/security.txt returns 404 on business-api.tiktok.com and ads.tiktok.com, 401 on developers.tiktok.com, and HTTP 200 with a generic SPA shell on www.tiktok.com (the same 32,656-byte body every unknown path returns there — a soft 404, not a document). The programme is real; the machine-readable pointer to it is missing. accepted_vulnerability_classes: - control flow hijacking - user data leaks - OWASP Top Ten issues - authentication or authorization vulnerabilities - access to internal resources - open redirects with security impact - anti-automation bypasses - arbitrary code execution evidence: - source: https://support.tiktok.com/en/safety-hc/reporting-security-vulnerabilities/reporting-the-security-vulnerabilities kind: vulnerability-reporting-policy http_status: 200 quote: >- "If you believe you have discovered a security bug or vulnerability on the TikTok app or website, please submit your report here. You will be redirected to the website of HackerOne, our trusted security bug bounty partner." — and "TikTok follows a Coordinated Disclosure Policy." - source: https://hackerone.com/tiktok kind: bug-bounty-program http_status: 200 - source: https://business-api.tiktok.com/.well-known/security.txt kind: security.txt probe http_status: 404