GetMyHotelsGetMyHotels.com
DestinationsHow it worksGet the appClaude & ChatGPT
GetMyHotels.com

AI-native hotel and flight booking. Tell us where, we handle the rest.

Discover

  • Search hotels
  • Destinations
  • Get the app
  • Claude & ChatGPT
  • Blog

Help

  • Help center
  • FAQs
  • Contact support

Company

  • About
  • Careers
  • Press

Legal

  • Terms
  • Privacy
  • Cookies
© 2026 GetMyHotels. All rights reserved.
TermsPrivacyYour privacy choicesComplianceLegalDelete accountSitemap
Back to legal
Security

Vulnerability disclosure

We welcome reports from security researchers who help us keep GetMyHotels safe. This page explains how to reach us, what's in scope, what we promise back, and the safe-harbor terms for good-faith testing. Last updated 2026-05-27.

security@getmyhotels.comsecurity.txt
Acknowledge
≤ 3 business days

Initial human reply confirming we've received and triaged the report.

Triage decision
≤ 10 business days

Confirmation that the report is valid, duplicate, out-of-scope, or needs more info.

Fix & disclose
≤ 90 days for High/Critical

Patch released and you're credited (with consent) in our acknowledgments list.

What we want to hear about

  • Authentication or session-management flaws (account takeover, session fixation)
  • Server-side injection (SQL, command, SSRF, template, prototype pollution)
  • Authorization bypass — accessing data or actions for another tenant / user
  • Payment manipulation, refund abuse, or pricing flaws
  • Sensitive data exposure (PII, payment tokens, internal credentials)
  • Stored XSS or HTML injection that affects other users
  • Subdomain takeover, exposed cloud resources, leaked secrets in code
  • Logic flaws in the AI agent or its tools (e.g. prompt injection leading to privileged actions)

Out of scope

  • Self-XSS or social-engineering reports
  • Missing security headers (CSP, HSTS subdomain inclusion) without demonstrated impact
  • Reports generated solely from automated scanners with no triage
  • Rate-limit hardening suggestions absent an actual abuse scenario
  • Findings that require physical access, malware, or compromised user devices
  • Denial-of-service attacks of any kind — please don't test these
  • Issues only reachable via outdated browser versions or unsupported configurations
  • Third-party SaaS we use as sub-processors (report those to the vendor; we'll help coordinate)

Safe harbor

As long as your testing follows the rules below, we won't pursue legal action against you for good-faith security research, treat your activity as a Terms of Service violation, or work to have you prosecuted under the Computer Fraud and Abuse Act or equivalent foreign laws:

  • Test only with accounts and data that belong to you.
  • If you accidentally encounter another user's data, stop, don't download or share it, and tell us immediately.
  • No social engineering of GetMyHotels employees, contractors, suppliers, or users.
  • No denial-of-service, distributed or otherwise.
  • Don't exfiltrate more data than the minimum needed to demonstrate impact.
  • Give us reasonable time to fix before any public disclosure.

What you get back

  • A human reply, fast, with the same engineer staying on the thread.
  • Credit in our acknowledgments list (with the name or handle you prefer).
  • GetMyHotels does not run a paid bug bounty program. We don't offer monetary rewards. We do reply to every report, fix what we can, and credit researchers publicly.

How to write a useful report

  1. Title with the class of bug and the impact.
  2. Steps to reproduce — exact URLs, payloads, accounts used.
  3. Impact in plain English: what can an attacker do to a user?
  4. Suggested fix if you have one (optional, helpful).
  5. Your preferred name or handle for credit, plus how to reach you.

PGP isn't required, but if you want it for sensitive details, email security@getmyhotels.com first and we'll exchange keys.

Acknowledgments

We'll list researchers who reported valid vulnerabilities here, newest first, with the name or handle they chose. Be the first — send us something.