generated: '2026-09-10' method: probed source: https://fisglobal.com/.well-known/security.txt program: exists: true type: bug-bounty platform: Bugcrowd name: 'Bug Bounty: FIS' url: https://bugcrowd.com/engagements/fis http_status: 200 managed: true policy: url: https://www.fisglobal.com/en/responsible-disclosure title: Vulnerability Disclosure http_status: 200 note: >- Reachable in a browser; the page is server-rendered behind Akamai bot management and resets the connection for a plain crawler, so it was confirmed through a rendering fetch rather than curl. Per the enrichment contract a bot challenge is not a dead pointer. security_txt: url: https://fisglobal.com/.well-known/security.txt http_status: 200 file: ../well-known/fis-security.txt rfc: RFC 9116 fields: Contact: https://www.fisglobal.com/en/responsible-disclosure Expires: '2023-12-31T18:00:00.000Z' Acknowledgments: https://bugcrowd.com/fis/hall-of-fame Preferred-Languages: en Policy: https://www.fisglobal.com/en/responsible-disclosure Hiring: https://careers.fisglobal.com/ deviations: - id: expired detail: The Expires field lapsed on 2023-12-31; RFC 9116 says clients should consider the file stale after that date. The document is still served unchanged as of 2026-09-10. - id: content-type detail: Served as text/html (the edge wraps the plain-text body in
), not the text/plain required by RFC 9116 ยง3. served_on: - fisglobal.com - developer.fisglobal.com - api-dev-uat.fisglobal.com - api-gw-ui-uat.fisglobal.com acknowledgments: hall_of_fame: https://bugcrowd.com/fis/hall-of-fame contact: email: null note: security.txt gives a web form (the responsible-disclosure page) rather than an email address. evidence: - url: https://fisglobal.com/.well-known/security.txt status: 200 fetched: '2026-09-10' - url: https://bugcrowd.com/engagements/fis status: 200 fetched: '2026-09-10' - url: https://www.fisglobal.com/en/responsible-disclosure status: 200 fetched: '2026-09-10'