Earlier quoted context omitted.
H1 could make it a proviso if using their service that rejected but reports are automatically disclosed.
1. The overwhelming majority of rejected H1 reports are garbage. 2. It is not the case that all reporters want their findings disclosed publicly, even if they're rejected. 3. Reporters already retain the right to publish findings however they'd like. The worst H1 or a client can do is kick you off the platform. 4. A bug bounty platform that mandated disclosure of any sort would lose all its customers to the platform…
As a hacker on hackerone, this is not my understanding of the relationship. Generally speaking the programs give you "authorized access" under the CFAA conditional on following the disclosure guidelines. I don't know about for other countries, but for the US I'm pretty sure this means that breaking the guidelines means you've retroactively committed a felony.
Now seems a little questionable about if any federal prosecutor would actually take the case, but it definitely doesn't seem like a strictly civil issue to me.
Strongly agree on all other points though.