generated: '2026-08-26' method: searched source: https://trust.savvymoney.com/ program: present: true name: Responsible Disclosure type: responsible-disclosure published_at: https://trust.savvymoney.com/ bug_bounty: false bug_bounty_platform: null bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti program was found for savvymoney.com. The trust center describes a Responsible Disclosure practice as part of its application security section but does not publish a scope, safe-harbour statement or reward table. contact: email: security@savvymoney.com source: https://trust.savvymoney.com/ security_txt: present: false note: >- /.well-known/security.txt returned 404 on www.savvymoney.com, creditscore.savvymoney.com and creditscoretest.savvymoney.com, 401 on hub.savvymoney.com, and 404 (unrouted host) on api.savvymoney.com. RFC 9116 is not served anywhere on the estate, so the published security contact is discoverable only by a human reading the trust center. evidence: - url: https://trust.savvymoney.com/ status: 403 note: Cloudflare challenge to curl; rendered fetch shows the Responsible Disclosure section and security@savvymoney.com. - url: https://www.savvymoney.com/.well-known/security.txt status: 404 - url: https://hub.savvymoney.com/.well-known/security.txt status: 401