Vulnerability Reporting Policy
Report a Security Vulnerability
At Bright Horizons our top priority is the safety, security and control of our customers' data. To excel at this, we welcome the vital role that security researchers play in keeping systems and data safe. To encourage the responsible reporting of potential security vulnerabilities, the Bright Horizons security team has committed to working with the community to verify, reproduce and respond to legitimate reports.
If you believe you've identified a potential security vulnerability in any Bright Horizons services, please report it to us right away using the form below. We will investigate all legitimate reports and do our best to quickly address the problems.
Please do not disclose your findings until we have had the opportunity to review and address them with you. Bright Horizons will consider the researcher's request to make a public disclosure but reserves the right to deny such disclosure requests. We appreciate your help in keeping Bright Horizons secure for our community.
Responsible Disclosure Guidelines
To encourage responsible disclosure, Bright Horizons will not initiate any legal action against security researchers for assessing vulnerabilities as long as they adhere to this policy, including the following guidelines:
- If you work for a Bright Horizons client, you are prohibited from conducting any testing under this program.
In that case, email security@brighthorizons.com to share your comments or concerns. - Bright Horizons has partnered with HackerOne for our vulnerability disclosure program. Notify Bright Horizons and provide all details of vulnerabilities you find using the HackerOne form below.
- Provide all details including the Bright Horizons account username if applicable, IP address or URL and the date/timestamp of the vulnerability to support validation and reproduction of the issue.
- Do not interact with an enterprise and/or personal Bright Horizons account that you don't own (such as by modifying or accessing data from the account).
- Do not access or attempt to access data that does not belong to you.
- Do not exploit a security issue you discover for any reason. (This includes demonstrating additional risk, such as attempted compromise of sensitive data or probing for additional issues.)
- Do not perform actions that may negatively affect Bright Horizons or its users, such as: executing or attempting to execute any Denial of Service attack, posting, transmitting, uploading, linking to, sending or storing any malicious software and/or file, testing third-party applications, websites or services that integrate with or link to Bright Horizons applications.
- Do not conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure and employees of Bright Horizons.
- Do not test the physical security of Bright Horizons offices, employees, equipment, etc.
- Do not violate any law or disrupt or compromise any data that is not your own.
- Do not use a finding to compromise/exfiltrate/modify/destroy data or to pivot to other systems. Use a proof of concept only to demonstrate an issue.
- Do not engage in any activity that would be disruptive, damaging, or harmful to Bright Horizons, its brands, or its users. This includes social engineering, unsolicited messages, phishing, physical security, and any type of denial-of-service attacks, especially using automated tools.
- Do not test third-party websites, applications, or services that integrate with Bright Horizons services without their permission.
- Any illegal activity is prohibited.
- Do not publicly disclose vulnerabilities (sharing any details whatsoever with anyone other than authorized Bright Horizons employees) or otherwise share vulnerabilities with a third party without the express written permission of Bright Horizons.
- Do not contact Bright Horizons by any means in relation to this program (pre-validating reports, testing them, asking for updates, etc.). Instead, please use the form below.
- Notify us as soon as possible after you discover a real or potential security issue.
- If you inadvertently access other users' data in your testing, please let us know, and do not store any such user data.
- If possible, use X-BugBounty header in your testing requests. The value of the header can be anything, but preferably use your username, for example: X-BugBounty: whitehat@example.com.
- Use of automated tools and scanners is prohibited.
- If your actions have a significant impact on availability or system performance, we will block your access.
- By reporting a security bug or vulnerability, you give us the right to use your report for any purpose.
Public Acknowledgement Policy
At this time, Bright Horizons does NOT maintain a public facing list of externally reported issues and reporters.
Privacy
Your personal data is used and processed subject to Hacker One's Privacy Policy: https://www.hackerone.com/policies/privacy.
Qualifying issues
We're particularly interested in the following types of vulnerabilities and impacts:
- AI feature vulnerabilities that clearly demonstrate security risk, such as data exposure of other customers' data
- Remote code execution
- XSS resulting in access to sensitive data (e.g., session info)
- Insecure direct object reference resulting in access to sensitive data or functionality
- Business logic flaws that result in access to sensitive data or functionality
Out of scope
We are not interested in the following types of issues:
- Issues with public contact forms or support forms. Testing of those forms is prohibited
- Password leaks found on the internet, or credential stuffing attacks
- AI feature issues without demonstrable security impact, including: hallucinations, missing user confirmation prompts, bias, or prompt injection without security consequences
- Attacks requiring physical access to a users device
- Phishing
- Disclosure of known public files or directories (e.g., robots.txt)
- Missing DNS records (e.g.MX, DMARC, SPF)
- Banner disclosure on common/public services
- HTTP/TLS configuration issues without demonstrable impact
- Lack of Secure/HTTPOnly flags on non-sensitive cookies
- CSP, Security header configuration suggestions
- Presence of application or web browser 'autocomplete' or 'save password' functionality
- CSRF on forms that are available to anonymous users
- Username enumeration on login or forgot password pages
- Rate limit bypasses where throttling is not in place
- Unauthenticated cache purge
- API key disclosure without proven business impact
- Self-XSS that cannot be used to exploit other users
- Absence of password length limits
- Bypassing rate-limits or the non-existence of rate-limits
- Host header injection without proven business impact
- Attacks requiring man-in-the-middle or compromised user accounts
- Cookie bomb DoS
- CORS issues on APIs
Scope
This policy applies to the following domains, subdomains, APIs, mobile apps:
- brighthorizons.com and all subdomains (*.brighthorizons.com)
- edassist.com and all subdomains (*.edassist.com)
- brighthorizons.co.uk and all subdomains (*.brighthorizons.co.uk)
- sittercity.com and all subdomains (*.sittercity.com)
- steveandkatescamp.com and all subdomains (*.steveandkatescamp.com)
- jovie.com and all subdomains (*.jovie.com)
- Any API endpoints hosted on any of the above domains
Any systems or services not expressly listed above are excluded from the scope and are not authorized for testing.
Issues reporting
Please submit your report at our VDP page on HackerOne: https://hackerone.com/bright_horizons_vdp?type=team
Legal terms
In connection with your participation in this program, you agree to comply with this policy, the HackerOne Code of Conduct https://www.hackerone.com/policies/code-of-conduct and all applicable laws and regulations, including any laws or regulations governing privacy or the lawful processing of data.
Policy Changes
Bright Horizons may cancel this program or change this policy at any time. If you are not reading this policy on a Bright Horizons website, review the current version of the policy at https://www.brighthorizons.com/about/privacy-security/vdp before performing any vulnerability testing or taking any other action based on the policy.
Safe harbor
Bright Horizons will not initiate a lawsuit or law enforcement investigation against you in response to reporting a vulnerability if you fully comply with this policy.
Policy last updated on this date: May 27, 2026