Either
"Hi, we do have a bug bounty program, please submit through the link here... Please note, disclosure and all further communication must be through the bug bounty portal"
or
"Hi, unfortunately we do not have a bug bounty program or other compensation, but we would love to address the vulnerability you found, please send details to ..."
That could be you, or a security team mailing list or whatever is appropriate.
Most likely, they'll tell you your site is missing browser security headers or something that they found with a vulnerability scanner, but sometimes there's good reports. Sometimes they'll try to get you to do ad-hoc compensation, which I would refuse (smells like extortion).