generated: '2026-07-23' method: searched probe: true source: https://www.aldermore.co.uk/.well-known/security.txt policy: [] contact: - securityresearch@aldermore.co.uk expires: '2027-01-31T00:00:00.000Z' notes: >- Aldermore Bank publishes an RFC 9116 security.txt at https://www.aldermore.co.uk/.well-known/security.txt directing security researchers to securityresearch@aldermore.co.uk. The file asks reporters not to include sensitive information in the initial email; a secure communication channel is provided in the reply. No public bug-bounty program (HackerOne/Bugcrowd/Intigriti) or standalone responsible-disclosure page was found. Note: the security.txt fields are comment-prefixed (each line begins with '#'), so strict RFC 9116 parsers may not extract Contact/Expires automatically, though the intent is unambiguous. evidence: - source: well-known/aldermore-security.txt kind: security.txt contact: securityresearch@aldermore.co.uk