Acknowledge
≤ 3 business days
Initial human reply confirming we've received and triaged the report.
Triage decision
≤ 10 business days
Confirmation that the report is valid, duplicate, out-of-scope, or needs more info.
Fix & disclose
≤ 90 days for High/Critical
Patch released and you're credited (with consent) in our acknowledgments list.
What we want to hear about
- Authentication or session-management flaws (account takeover, session fixation)
- Server-side injection (SQL, command, SSRF, template, prototype pollution)
- Authorization bypass — accessing data or actions for another tenant / user
- Payment manipulation, refund abuse, or pricing flaws
- Sensitive data exposure (PII, payment tokens, internal credentials)
- Stored XSS or HTML injection that affects other users
- Subdomain takeover, exposed cloud resources, leaked secrets in code
- Logic flaws in the AI agent or its tools (e.g. prompt injection leading to privileged actions)
Out of scope
- Self-XSS or social-engineering reports
- Missing security headers (CSP, HSTS subdomain inclusion) without demonstrated impact
- Reports generated solely from automated scanners with no triage
- Rate-limit hardening suggestions absent an actual abuse scenario
- Findings that require physical access, malware, or compromised user devices
- Denial-of-service attacks of any kind — please don't test these
- Issues only reachable via outdated browser versions or unsupported configurations
- Third-party SaaS we use as sub-processors (report those to the vendor; we'll help coordinate)
Safe harbor
As long as your testing follows the rules below, we won't pursue legal action against you for good-faith security research, treat your activity as a Terms of Service violation, or work to have you prosecuted under the Computer Fraud and Abuse Act or equivalent foreign laws:
- Test only with accounts and data that belong to you.
- If you accidentally encounter another user's data, stop, don't download or share it, and tell us immediately.
- No social engineering of GetMyHotels employees, contractors, suppliers, or users.
- No denial-of-service, distributed or otherwise.
- Don't exfiltrate more data than the minimum needed to demonstrate impact.
- Give us reasonable time to fix before any public disclosure.
What you get back
- A human reply, fast, with the same engineer staying on the thread.
- Credit in our acknowledgments list (with the name or handle you prefer).
- GetMyHotels does not run a paid bug bounty program. We don't offer monetary rewards. We do reply to every report, fix what we can, and credit researchers publicly.
How to write a useful report
- Title with the class of bug and the impact.
- Steps to reproduce — exact URLs, payloads, accounts used.
- Impact in plain English: what can an attacker do to a user?
- Suggested fix if you have one (optional, helpful).
- Your preferred name or handle for credit, plus how to reach you.
PGP isn't required, but if you want it for sensitive details, email security@getmyhotels.com first and we'll exchange keys.
Acknowledgments
We'll list researchers who reported valid vulnerabilities here, newest first, with the name or handle they chose. Be the first — send us something.