generated: '2026-09-10' method: probed probe: true source: well-known/freddie-mac-api-security.txt security_txt: url: https://api.freddiemac.com/.well-known/security.txt http_status: 200 content_type: text/plain fetched: '2026-09-10' mirror: url: https://api-test.freddiemac.com/.well-known/security.txt http_status: 200 note: Byte-identical apart from its own Canonical line; the UAT gateway serves the same policy. fields_present: - Canonical - Contact - Expires - Preferred-Languages fields_absent: - Policy - Encryption - Acknowledgments - Hiring - CSAF expires: '2027-06-30' expires_valid: true note: RFC 9116 compliant and current. It is served ONLY from the two Apigee API gateway hosts. www.freddiemac.com, sf.freddiemac.com, mf.freddiemac.com, capitalmarkets.freddiemac.com and guide.freddiemac.com all 404 on /.well-known/security.txt, and developer.freddiemac.com answers 401 on the whole /.well-known/ space, so a researcher landing on any Freddie Mac property other than the API gateway finds nothing. contact: - mailto:freddie-mac@submit.bugcrowd.com - https://privacyportal.onetrust.com/incident-portal/webforms/94b5e41a-aba0-4e51-ba48-efa19ce560a1/1b25c37a-a280-44f2-b61e-a693a33c7267 bug_bounty: true bug_bounty_platform: Bugcrowd bug_bounty_note: 'The Contact line routes submissions to freddie-mac@submit.bugcrowd.com, which is a Bugcrowd-managed intake address. There is no public program page: https://bugcrowd.com/freddie-mac returned 404 on 2026-09-10, so the engagement is private/invite-only rather than an open public bounty.' policy_published: false policy_note: 'No Policy: field is published, so a researcher is told where to send a report but not what scope, safe-harbour or response commitment applies.' evidence: - source: well-known/freddie-mac-api-security.txt kind: security.txt harvested verbatim 2026-09-10 url: https://api.freddiemac.com/.well-known/security.txt http_status: 200 - url: https://bugcrowd.com/freddie-mac http_status: 404 kind: no public Bugcrowd program page - the program is private recommendation: 'Serve the same security.txt from www.freddiemac.com and sf.freddiemac.com, and add a Policy: line. Today the file only exists on the two hosts a researcher is least likely to browse to.'