generated: '2026-08-12' method: searched probe: true source: https://www.findigs.com/legal/responsible-disclosure-policy policy: - https://www.findigs.com/legal/responsible-disclosure-policy contact: - security@findigs.com bug_bounty: false bug_bounty_platform: null safe_harbor: partial program: name: Findigs Responsible Disclosure Policy reporting_channel: email reporting_address: security@findigs.com disclosure_expectation: >- Researchers are asked to give Findigs a reasonable amount of time to resolve the issue before disclosing it publicly or to a third party, and to interact only with accounts they own or have explicit permission to test. conduct_requirements: - Avoid violating privacy, destroying data, or interrupting or degrading the Findigs service. out_of_scope: - Distributed Denial of Service (DDoS) attacks - Spamming - Social engineering or phishing targeting Findigs employees - Attacks against physical property or data centers response_commitment: Findigs states it will respond as soon as possible. evidence: - {source: 'https://www.findigs.com/legal/responsible-disclosure-policy', kind: disclosure-policy-page, http_status: 200} - {source: 'dig CAA findigs.com', kind: caa-iodef, value: '0 iodef "mailto:security@findigs.com"'} - {source: 'https://www.findigs.com/legal/information-security-addendum', kind: information-security-program, http_status: 200} note: >- Findigs serves NO RFC 9116 /.well-known/security.txt on any host (see well-known/findigs-well-known.yml — 404 everywhere). The disclosure program exists only as an HTML legal page. The security contact is independently corroborated out-of-band by the findigs.com CAA iodef record, which names the same mailbox. No bug bounty program on HackerOne, Bugcrowd or Intigriti was found. The separate Information Security Addendum (https://www.findigs.com/legal/information-security-addendum) describes an internal security program — periodic risk assessments, firewall/antivirus/patch management/intrusion detection, and at least annual review of safeguard effectiveness — but names no third-party certification.