generated: '2026-09-07' method: searched source: https://www.fanniemae.com/about-us/reporting-technology-vulnerability note: >- Fannie Mae runs a first-party vulnerability disclosure channel — a published policy page and an intake form on its own domain. It does NOT run a bug bounty. The hackerone.com/fanniemae page that turns up in search is HackerOne's community-curated, explicitly UNCLAIMED directory entry (the page carries class "spec-external-unclaimed" and describes itself as "community-curated"); it is recorded here as a third-party listing, not as a Fannie Mae program. program: exists: true type: vulnerability-disclosure-policy bug_bounty: false first_party: true policy_url: https://www.fanniemae.com/about-us/reporting-technology-vulnerability policy_status: 200 submission_form: https://www.fanniemae.com/form/report-technology-vulnerability submission_form_status: 200 security_txt: null security_txt_note: >- /.well-known/security.txt returns 404 on www.fanniemae.com, fanniemae.com and fmsso.fanniemae.com. The disclosure channel exists but is not machine-discoverable — publishing an RFC 9116 security.txt pointing at the existing form would close this with no new process. contact_email: iso_support@fanniemae.com contact_email_source: >- CAA iodef record on fanniemae.com — 128 iodef "mailto: iso_support@fanniemae.com" (see security/fannie-mae-domain-security.yml). This is the incident contact Fannie Mae publishes in DNS. submission_requirements: - Name, organization and contact information - Description of the vulnerability - Technical details stated_terms: - Reporters are instructed not to include nonpublic personal information (SSNs, financial account numbers) in a report. - Fannie Mae may share a report with law enforcement agencies or other industry participants. - Fannie Mae states it may not respond to the reporter or keep them apprised of the report's validity. - Vulnerabilities involving potential bodily harm should be reported to law enforcement immediately. safe_harbor: false safe_harbor_note: The policy page carries no explicit safe-harbor or researcher legal-protection language. third_party_listings: - platform: HackerOne url: https://hackerone.com/fanniemae status: 200 claimed_by_provider: false kind: community-curated directory entry related: cybersecurity_requirements: https://www.fanniemae.com/about-us/corp-responsibility/governance/information-security-and-business-resiliency-supplement cybersecurity_requirements_status: 200 cybersecurity_requirements_note: >- Requirements Fannie Mae imposes on its sellers, servicers and technology partners (including a 36-hour cybersecurity incident notification obligation) — an obligation Fannie Mae places on others, not a certification Fannie Mae holds. It is deliberately NOT recorded as a trust center or compliance attestation. trust_center: exists: false note: >- No trust center, no published SOC 2 / ISO 27001 / PCI / FedRAMP attestation, and no compliance portal was found on any fanniemae.com host (probe-security-programs.py 2026-09-07 returned vdp=none trust=none; this file is the manual upgrade of its vdp result). Fannie Mae is a government-sponsored enterprise supervised by FHFA; its published governance material is regulatory, not a customer-facing certification set.