generated: '2026-08-12' method: searched probe: true source: https://www.fintech-farm.com/security docs: https://www.fintech-farm.com/security program: type: vulnerability-disclosure-policy bounty: false bounty_note: >- No monetary reward or bug bounty is offered; the page describes a coordinated-disclosure program only. Not hosted on HackerOne, Bugcrowd or Intigriti — Fintech Farm runs it directly over email. platform: self-hosted security_txt: present: true standard: RFC 9116 url: https://www.fintech-farm.com/.well-known/security.txt file: well-known/fintech-farm-security.txt http_status: 200 content_type: text/plain expires: '2027-06-13T23:59:59.000Z' canonical: https://fintech-farm.com/.well-known/security.txt preferred_languages: - en - uk - ru policy: - https://www.fintech-farm.com/security contact: - mailto:security@fintech-farm.com - https://www.fintech-farm.com/security contact_hours: Mon-Fri, 09:00-18:00 UTC+2 encryption: pgp_key: null note: >- No PGP key is published. The policy asks researchers who need to send encrypted material to email first so a secure channel can be arranged. sla: - stage: acknowledgement target: 5 business days - stage: initial assessment target: 10 business days - stage: coordinated disclosure target: 90 days scope: in_scope: - mobile applications - web applications - public APIs - backend services - SDKs and integration libraries - authentication infrastructure out_of_scope: - third-party services - denial-of-service testing - social engineering - physical attacks - theoretical issues without a practical proof of concept report_requirements: - the affected product, URL or API and where it was discovered - reproduction steps and demonstrated impact - proof-of-concept material, samples or screenshots - attribution preference safe_harbor: offered: true text: >- We will not pursue or support legal action against security researchers who discover and report vulnerabilities in good faith and in accordance with this policy. advisories: published: false note: >- The page states no security advisories are currently published; interim mitigation guidance is given on the page itself. note: >- Notable finding: Fintech Farm publishes no developer program and no public API contract, yet its disclosure policy explicitly names "public APIs" and "SDKs and integration libraries" as in scope. The integration surface exists and is described as public in the security policy, but it is not documented anywhere a member of the public can reach. evidence: - source: https://www.fintech-farm.com/.well-known/security.txt kind: security.txt (live probe) http_status: 200 - source: https://www.fintech-farm.com/security kind: published vulnerability disclosure policy page http_status: 200