generated: '2026-08-29' method: searched source: https://corporate.abercrombie.com/vulnerability-disclosure/ program: published: true name: Abercrombie & Fitch Co. Vulnerability Disclosure policy_url: https://corporate.abercrombie.com/vulnerability-disclosure/ policy_status: 200 platform: HackerOne platform_url: https://hackerone.com/abercrombie_fitch platform_status: 200 intake: hackerone scope: >- Stated on the corporate policy page as apps or sites associated with Abercrombie & Fitch Co. The itemized in-scope asset list is maintained on the HackerOne program page rather than on the corporate page. bounty: unknown safe_harbor: not-stated response_sla: not-stated pgp_key: null security_txt: false discovery: security_txt_probed: - url: https://www.abercrombie.com/.well-known/security.txt status: 403 note: edge bot challenge answers 403 on every path including the site root - url: https://corporate.abercrombie.com/.well-known/security.txt status: 404 - url: https://api.anfcorp.com/.well-known/security.txt status: 404 gaps: - No RFC 9116 security.txt is served at any Abercrombie & Fitch host, so the program is discoverable only by finding the corporate page or the HackerOne listing. - The corporate policy page states neither safe-harbor language nor a response-time commitment; both live (if anywhere) inside the HackerOne policy.