| CARVIEW |
Select Language
HTTP/2 200
content-type: text/html
date: Sun, 18 Jan 2026 17:41:51 GMT
last-modified: Sun, 04 Jan 2026 18:43:27 GMT
etag: W/"0682115cec7920ebea398b86fe574483"
x-amz-server-side-encryption: AES256
x-amz-version-id: f2UxHC19eBUTMYHWYdCkeSKtmz48pbpG
server: AmazonS3
content-encoding: gzip
vary: Accept-Encoding
via: 1.1 23c7c0fcb7588dda47ad1ecde462c110.cloudfront.net (CloudFront)
x-xss-protection: 1; mode=block
x-frame-options: DENY
referrer-policy: strict-origin-when-cross-origin
content-security-policy: frame-ancestors 'none'
x-content-type-options: nosniff
strict-transport-security: max-age=63072000; includeSubDomains; preload
permissions-policy: microphone=(), camera=(), geolocation=(self)
vary: Origin
set-cookie: geo=KA; Path=/; Secure; SameSite=Lax
x-cache: Miss from cloudfront
x-amz-cf-pop: BOM78-P3
x-amz-cf-id: ArRf5Uwm0eD0P--W8ZsspxPTc6A3QwLccR9jiuXqEU9Uv4xPSS8g-w==
Bug Bounty Program | Manhattan Institute
52 Vanderbilt Avenue
New York, NY 10017
New York, NY 10017
(212) 599-7000
info@manhattan-institute.org
info@manhattan-institute.org
Bug Bounty Program
Last Update: July 22, 2025
Security Vulnerability Disclosure & Bounty Disclaimer
The Manhattan Institute encourages responsible reporting of any security issues you discover. To submit a vulnerability report and be considered for a bug bounty award please note the following:
- Critical Severity Only: Reports must involve a vulnerability that could lead to significant impact
- Submission Guidelines: Send your findings to bounty@manhattan.institute with:
- A clear description of the issue
- Step-by-step reproduction instructions or proof-of-concept
- Any scripts, logs, or screenshots that demonstrate the flaw
- Your full legal name
- Valid government-issued photo ID
- A completed IRS Form W-9 (for U.S. individuals) or Form W-8BEN (for non-U.S. individuals)
- Evaluation & Payout: All reports are reviewed on a case-by-case basis. Only qualifying, critical vulnerabilities will be eligible for bounty awards. Payment amounts and eligibility are determined at the Institute’s discretion based on impact, novelty, and completeness of your submission. The Manhattan Institute reserves the right to withdraw any submissions that do not meet these standards and guidelines.
- Legal Safe Harbor: In compliance with this policy, and for the purpose of criminal statutes, good-faith investigation of security vulnerabilities on MI’s properties, which are promptly reported with sufficient detail, will not be treated as intentional hacking attempts.
- Zero-Tolerance for Threats or Fraud: Any attempts to coerce, threaten, harass, or defraud Institute personnel will result in immediate removal from our bug bounty program and permanent ineligibility for any current or future bounty payments.
Thank you for helping us keep our community safe.
Copyright © 2026 Manhattan Institute for Policy Research, Inc. All rights reserved.
Copyright © 2026 Manhattan Institute for Policy Research, Inc. All rights reserved.
EIN #13-2912529