generated: '2026-07-25' method: searched probe: true source: https://www.lloyds.com/.well-known/security.txt description: >- Lloyd's runs a real, named Responsible Disclosure Programme. It publishes an RFC 9116 security.txt at the apex of its web estate with a working reporting mailbox, and a live hall-of-fame page crediting named researchers. There is no paid bug bounty and no third-party platform (HackerOne / Bugcrowd / Intigriti); the intake is a direct mailbox and the programme is deliberately low-friction - the security.txt comments explicitly decline to publish a PGP key "because we want to keep the route for reporting as open as possible". programme: name: Responsible Disclosure Programme operator: Corporation of Lloyd's bug_bounty: false platform: null safe_harbour_published: false policy: - https://www.lloyds.com/security-reports contact: - mailto:securityreporting@lloyds.com acknowledgments: url: https://www.lloyds.com/security-reports live: true status: 200 note: >- The security.txt carries the Acknowledgments line COMMENTED OUT with the annotation "(Program coming soon!)", but the page itself is now live and publishes a hall of fame. The security.txt has not been updated to uncomment it. preferred_languages: [en] canonical: https://www.lloyds.com/.well-known/security.txt encryption: null expires: null evidence: - source: https://www.lloyds.com/.well-known/security.txt kind: security.txt (live probe 2026-07-25) status: 200 file: well-known/lloyds-of-london-security.txt fields: [Contact, Preferred-Languages, Canonical] - source: https://www.lloyds.com/security-reports kind: acknowledgments / hall of fame (live probe 2026-07-25) status: 200 quote: >- "Responsible Disclosure Programme - We would like to thank all persons who make a responsible disclosure to us and recognise their valuable contribution in increasing the security of our products and services for our benefit and for the benefit of our customers by featuring those contributors in our hall of fame." gaps: - The security.txt publishes no Expires field, which RFC 9116 section 2.5.5 requires; parsers should treat the file as stale. - No Policy field is declared in the security.txt itself (the disclosure page is only referenced from a commented-out Acknowledgments line). - No Encryption key and no published safe-harbour / legal-protection statement for researchers. - The London Market API Gateway hosts (api / preprod-api / sand-api .londonmarketgroup.co.uk) publish no security.txt of their own - the API estate is not covered by a disclosure route on its own domain. related: - well-known/lloyds-of-london-well-known.yml - security/lloyds-of-london-domain-security.yml