generated: '2026-09-05' method: searched source: >- https://www.10xbanking.com/responsible-disclosure (HTTP 200) and the served https://www.10xbanking.com/.well-known/security.txt (HTTP 200, application/rtf). description: >- 10x Banking runs a published, non-monetary responsible disclosure programme with a dedicated intake address and explicit safe-harbour language. It is a policy, not a bug bounty, and it is not run through a platform (no HackerOne, Bugcrowd or Intigriti presence was found). program: type: responsible-disclosure-policy bug_bounty: false platform: none policy_url: https://www.10xbanking.com/responsible-disclosure policy_status: 200 contact: mailto:security-disclosures@10xbanking.com preferred_languages: en security_txt: url: https://www.10xbanking.com/.well-known/security.txt status: 200 file: ../well-known/10x-banking-technology-services-security.txt content_type: application/rtf signed: false fields: Contact: mailto:security-disclosures@10xbanking.com Expires: '2025-01-30T23:00:00.000Z' Preferred-Languages: en Hiring: https://www.10xbanking.com/job-vacancies defects: - >- Expired: the Expires field is 2025-01-30, more than a year before this probe. RFC 9116 says a consumer should not trust a security.txt past its Expires date. - >- Served as application/rtf with RTF control words in the body rather than the RFC 9116 required text/plain, so a parser reads control markup, not fields. - >- No Policy field, even though a policy page exists at https://www.10xbanking.com/responsible-disclosure. - No Encryption field and no detached OpenPGP signature. scope: in_scope: >- "all of 10x Banking's digital assets, including but not limited to websites, web applications, mobile applications, APIs, and any other services operated and owned by 10x Banking" out_of_scope: >- The 10xbanking.com marketing website itself — the policy states it "is considered hosted by a third party and is not in scope without explicit permission". safe_harbour: offered: true text: >- "10x Banking will not pursue legal action against individuals who report security vulnerabilities in accordance with this Responsible Disclosure Policy, provided they do so in good faith and comply with the guidelines outlined here" rewards: monetary: false text: >- "We do not, as a matter of course, offer monetary rewards for vulnerability reports" — recognition may be offered at 10x's discretion for valid, serious findings. notes: - >- No trust centre, no SOC 2 / ISO 27001 / PCI DSS certification page and no compliance portal were found on any 10x host or via search, so no Compliance pointer is claimed. For a core banking vendor serving Chase UK and Westpac these attestations almost certainly exist; they are simply not published to the open web.