generated: '2026-07-17' method: searched probe: true source: https://hackerone.com/safaricom contact: - https://hackerone.com/safaricom - mailto:bugbounty@safaricom.co.ke evidence: - source: https://hackerone.com/safaricom kind: HackerOne vulnerability disclosure policy note: >- Safaricom runs a HackerOne Vulnerability Disclosure Program. Reports are submitted through the HackerOne portal (bugbounty@safaricom.co.ke referenced for intake); public disclosure is not permitted, and high-impact researchers may be invited to a private bug bounty. No dedicated /.well-known/security.txt was found on safaricom.co.ke (301) or developer.safaricom.co.ke (404) on the probe date.