generated: '2026-09-05' method: probed source: https://www.citi.com/reporting-vulnerability (HTTP 200, title "Reporting a Vulnerability - Bank Security | Citi.com") and https://bugcrowd.com/engagements/citi (HTTP 200) published: true programs: - name: Citi Reporting a Vulnerability type: first-party disclosure page url: https://www.citi.com/reporting-vulnerability http_status: 200 fetched: '2026-09-05' note: Also served at https://online.citi.com/US/JRS/pands/detail.do?ID=ReportingVulnerability (HTTP 200, identical 113,380-byte body). - name: Citi's Responsible Disclosure Program type: managed vulnerability disclosure (VDP) platform: Bugcrowd url: https://bugcrowd.com/engagements/citi http_status: 200 fetched: '2026-09-05' evidence: og:title "Citi's Responsible Disclosure Program | Bugcrowd", og:url https://bugcrowd.com/engagements/citi, og:description "Learn more about Citi's Vulnerability Disclosure engagement powered by Bugcrowd", and a Citi-logo og:image on bugcrowd's CDN. bounty: engagement is labelled Vulnerability Disclosure rather than a paid bug bounty; the program body is JavaScript-rendered and was not readable anonymously, so reward terms are NOT asserted here. security_txt: published: false note: No /.well-known/security.txt on any of the 8 Citi hosts probed. See well-known/citi-well-known.yml. dns_security: security/citi-domain-security.yml caa_iodef: value: mailto:CAADNS@citi.com note: Citi publishes a CAA iodef contact in DNS, a second machine-readable security reporting channel. source: security/citi-domain-security.yml