We welcome reports from security researchers who help us keep GetMyHotels safe. This page explains how to reach us, what's in scope, what we promise back, and the safe-harbor terms for good-faith testing. Last updated 2026-05-27.
As long as your testing follows the rules below, we won't pursue legal action against you for good-faith security research, treat your activity as a Terms of Service violation, or work to have you prosecuted under the Computer Fraud and Abuse Act or equivalent foreign laws:
PGP isn't required, but if you want it for sensitive details, email security@getmyhotels.com first and we'll exchange keys.
We'll list researchers who reported valid vulnerabilities here, newest first, with the name or handle they chose. Be the first — send us something.