Bug bounty platforms can often be misused as NDA as a service. As a general rule, I avoid reporting via bbp for this very reason
why would i report free bugs to bugcrowd vdp just for vendors to say “never disclose”? that disclosure policy is not it.
better to go security@ with project zero deadlines, 90 days, then i share it with the community.