generated: '2026-07-19' method: searched probe: true policy: - https://global.flixbus.com/responsible-disclosure contact: - mailto:responsible-disclosure@flixbus.com encryption: https://responsible-disclosure.security.flix.tech/pgp.txt preferred_languages: [de, en] security_txt: well-known/flix-security.txt security_txt_expires: '2027-05-04T00:00:00Z' bug_bounty: false bug_bounty_note: >- Flix runs a self-managed coordinated vulnerability-disclosure program and does not currently offer bug bounties or other compensation. Reports are handled directly by email (no HackerOne/Bugcrowd/Intigriti platform). scope: >- All FlixBus digital products, including mobile applications and web services. disclosure_terms: >- Researchers are asked to give Flix reasonable time to investigate and remediate before publishing findings; Flix commits to publishing security advisories (vulnerability description, affected versions, severity, guidance) upon fix. evidence: - {source: well-known/flix-security.txt, kind: security.txt} - {source: https://global.flixbus.com/responsible-disclosure, kind: disclosure-page}