generated: '2026-08-04' method: searched source: https://global.flixbus.com/.well-known/security.txt policy: - https://global.flixbus.com/responsible-disclosure contact: - mailto:responsible-disclosure@flixbus.com encryption: - https://responsible-disclosure.security.flix.tech/pgp.txt preferred_languages: - de - en canonical: https://global.flixbus.com/.well-known/security.txt expires: '2027-05-04T00:00:00Z' security_txt: present: true rfc: RFC 9116 file: well-known/flixbus-security.txt hosts_serving_it: - https://global.flixbus.com/.well-known/security.txt - https://www.flixbus.com/.well-known/security.txt - https://flixbus.com/.well-known/security.txt bug_bounty: offered: false note: >- The policy states explicitly that Flix does not currently offer bug bounties or other compensation for reported vulnerabilities. No HackerOne, Bugcrowd or Intigriti program was found. program: scope: All FlixBus digital products, including mobile applications and web services. safe_harbor: >- Not explicitly granted. The policy asks researchers to allow reasonable time to investigate and remediate before publishing findings, but does not state legal safe-harbor protection. advisories: >- Flix states it publishes security advisories describing the vulnerability, affected versions, severity and user guidance when a fix is released. evidence: - source: https://global.flixbus.com/.well-known/security.txt kind: security.txt http_status: 200 content_type: text/plain fetched: '2026-08-04' - source: https://global.flixbus.com/responsible-disclosure kind: disclosure-policy-page http_status: 200 fetched: '2026-08-04' - source: https://responsible-disclosure.security.flix.tech/pgp.txt kind: pgp-key http_status: 200 content_type: text/plain fetched: '2026-08-04'