generated: '2026-07-25' method: searched probe: true source: https://www.confused.com/privacy-and-security/security/security-disclosure-policy note: >- Admiral Group plc itself publishes no vulnerability-disclosure policy that is reachable to automated clients - www.admiralgroup.co.uk is bot-protected and admiral.com serves no /.well-known/security.txt and no /security or /responsible-disclosure page. The one real disclosure program across the group belongs to Confused.com, the price-comparison brand wholly owned by Admiral Group plc, which publishes an RFC 9116 security.txt pointing at a full written security disclosure policy. It is recorded here under the group record because no separate Confused.com provider record exists in the network. brand: Confused.com (Admiral Group plc) policy: - https://www.confused.com/privacy-and-security/security/security-disclosure-policy contact: - mailto:security@confused.com security_txt: url: https://www.confused.com/.well-known/security.txt file: well-known/admiral-group-security.txt status: 200 expires: '2027-07-15T01:00:00Z' preferred_languages: en fields: canonical: false encryption: false acknowledgments: false hiring: false bug_bounty: program: false platform: null note: >- No HackerOne, Bugcrowd or Intigriti program was found for Admiral Group, Confused.com or Veygo. Reporting is direct to security@confused.com. safe_harbor: true safe_harbor_note: >- The policy states Confused.com "agrees not to take any legal action against you as long as you follow the guidelines in this Policy." response_commitment: Security team confirms receipt of a submission within two working days. guidelines: - Act in good faith; only target your own accounts and data. - No testing against partners, and no testing that causes disruption or additional cost (no DDoS, crash or unresponsiveness attempts, or fuzzing). - Never view, change or delete data other than your own; never delete data at all. - Do not exploit a vulnerability to gain further access to systems or data. - No social engineering of staff and no attempts at physical access to sites or systems. - Do not break the law. - Keep vulnerability information confidential between the reporter and Confused.com. evidence: - source: well-known/admiral-group-security.txt kind: security.txt (RFC 9116, harvested verbatim) - source: https://www.confused.com/.well-known/security.txt kind: live probe status: 200 - source: https://www.confused.com/privacy-and-security/security/security-disclosure-policy kind: written disclosure policy page status: 200 negative_probes: - url: https://www.admiral.com/.well-known/security.txt status: 404 - url: https://www.admiral.com/security status: 404 - url: https://www.admiral.com/responsible-disclosure status: 404 - url: https://www.veygo.com/.well-known/security.txt status: 404 - url: https://www.admiralgroup.co.uk/.well-known/security.txt status: 000 note: Bot-protected; inconclusive rather than a confirmed absence.