generated: '2026-09-13' method: probed source: https://fisglobal.com/.well-known/security.txt note: >- IntelliMatch (FIS Data Integrity Manager) publishes no disclosure programme of its own. The programme recorded here is its vendor's, FIS, reached from the RFC 9116 security.txt served on fisglobal.com — the only domain the product is published on. Recorded as inherited from the parent, not as a product-level programme. scope: vendor-wide (FIS); covers this product by inheritance inherited_from: fis security_txt: url: https://fisglobal.com/.well-known/security.txt status: 200 file: ../well-known/intellimatch-security.txt fields: contact: https://www.fisglobal.com/en/responsible-disclosure policy: https://www.fisglobal.com/en/responsible-disclosure acknowledgments: https://bugcrowd.com/fis/hall-of-fame preferred_languages: en hiring: https://careers.fisglobal.com/ deviations: - Expires field lapsed 2023-12-31T18:00:00.000Z — RFC 9116 section 6.6 says clients should treat the file as stale - served as text/html rather than text/plain policy: url: https://www.fisglobal.com/en/responsible-disclosure status: 403 note: >- Named as both Contact and Policy by the security.txt. Behind Akamai bot management for our crawler (403 to curl); a browser-agent fetch reached the page and it renders a "Vulnerability Disclosure" heading with the substantive policy loaded client-side. Live, not dead. bug_bounty: platform: Bugcrowd url: https://bugcrowd.com/fis status: 200 hall_of_fame: https://bugcrowd.com/fis/hall-of-fame note: Probed directly and live. Programme is FIS-wide; per-product scope not published. safe_harbor: not-stated-in-security-txt