generated: '2026-09-10' method: searched source: https://hackerone.com/ford program: present: true name: Ford - Vulnerability Disclosure Program platform: HackerOne url: https://hackerone.com/ford http_status: 200 checked: '2026-09-10' type: coordinated disclosure (no monetary bounty) scope_note: >- Ford runs a coordinated vulnerability disclosure program on HackerOne. It is a disclosure program rather than a paid bounty. Ford's own Developer Programme Terms (section 9.1) separately prohibit probing or scanning the developer website and materials outside that program, so the HackerOne program is the sanctioned reporting channel. citation: https://developer.ford.com/assets/i18n/en.json (Ford Developer Programme Terms and Conditions, section 9. Website Security) history: - platform: Bugcrowd url: https://bugcrowd.com/engagements/ford http_status: 404 state: retired checked: '2026-09-10' note: Ford's earlier Coordinated Disclosure Program page no longer resolves; HackerOne is the current channel. security_txt: present: false probed: - url: https://developer.ford.com/.well-known/security.txt status: 404 - url: https://api.vehicle.ford.com/.well-known/security.txt status: 404 - url: https://api.mps.ford.com/.well-known/security.txt status: 503 - url: https://www.ford.com/.well-known/security.txt status: 0 note: connection terminated by the edge (bot mitigation) — unreachable, not confirmed absent note: >- Ford operates a disclosure program but does not advertise it with an RFC 9116 security.txt on any host we could reach. Publishing one at https://www.ford.com/.well-known/security.txt pointing at hackerone.com/ford would make the program machine-discoverable.