generated: '2026-07-23' method: searched probe: true source: https://www.hsbc.com/.well-known/security.txt note: >- first direct is a division of HSBC UK Bank plc; vulnerability disclosure is operated at the HSBC group level and applies to the first direct brand and its Open Banking surfaces. Verified from the RFC 9116 security.txt published at www.hsbc.com and the HSBC public Vulnerability Disclosure Programme on Bugcrowd. policy: - https://bugcrowd.com/engagements/hsbc-vdp-pro contact: - mailto:responsible-disclosure@hsbc.com - https://bugcrowd.com/engagements/hsbc-vdp-pro program: type: vulnerability-disclosure-programme platform: Bugcrowd url: https://bugcrowd.com/engagements/hsbc-vdp-pro preferred_languages: [en, pl, cn, es] evidence: - {source: well-known/first-direct-security.txt, kind: security.txt, field: 'Contact: https://bugcrowd.com/engagements/hsbc-vdp-pro'} - {source: 'https://www.hsbc.com/.well-known/security.txt', kind: security.txt, status: 200}