generated: '2026-08-17' method: searched probe: true source: https://ibanfirst.com/security-policy.html policy: - https://www.ibanfirst.com/security-policy.html contact: - mailto:security.txt@ibanfirst.com acknowledgments: https://www.ibanfirst.com/hall-of-fame.html encryption_key: https://www.ibanfirst.com/pgp-key.txt preferred_languages: en, fr scope: '*.ibanfirst.com' bug_bounty: present: false statement: >- "We do not currently have a Bug Bounty program" - the policy encourages responsible disclosure without a paid program. platform: null safe_harbor: published: false security_txt: served: true path: /.well-known/security.txt file: well-known/ibanfirst-security.txt spec: RFC 9116 expires: '2028-12-30T23:00:00.000Z' canonical: https://www.ibanfirst.com/.well-known/security.txt fields_present: - Contact - Expires - Encryption - Acknowledgments - Preferred-Languages - Canonical - Policy caa_iodef: 'mailto:security.caa@ibanfirst.com' evidence: - source: well-known/ibanfirst-security.txt kind: security.txt url: https://ibanfirst.com/.well-known/security.txt status: 200 - source: https://ibanfirst.com/security-policy.html kind: security policy page status: 200 keywords: [responsible disclosure, security.txt, bug bounty, access control, encryption, incident response] - source: https://ibanfirst.com/hall-of-fame.html kind: researcher acknowledgments status: 200 - source: https://ibanfirst.com/pgp-key.txt kind: PGP public key status: 200 note: >- A complete RFC 9116 posture: security.txt with all seven common fields, a linked policy page, a published PGP key, a researcher hall of fame, and an iodef contact in the domain's CAA record. No trust centre and no named third-party security certifications (no SOC 2, ISO 27001, PCI DSS or HIPAA claim was found anywhere on the public site) - see conformance/ibanfirst-conformance.yml.