specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: SoFi Technologies providerId: sofi-technologies generated: '2026-09-06' method: searched source: https://hackerone.com/sofi-1 description: >- SoFi Technologies runs a vulnerability disclosure program on HackerOne. The program is first-party - the HackerOne team profile for handle sofi-1 names SoFi and lists https://www.sofi.com/ as its website - and it accepts disclosure assistance. It is not advertised from a security.txt anywhere on SoFi's estate; the only way to find it is to know the platform. program: platform: HackerOne url: https://hackerone.com/sofi-1 team_name: Sofi team_handle: sofi-1 team_id: 76924 claimed_website: https://www.sofi.com/ allows_disclosure_assistance: true public_policy_readable: false policy_note: >- The policy body renders client-side; the page's own meta description states it "documents any known process for reporting a security vulnerability to Sofi, often referred to as vulnerability disclosure (ISO 29147), a responsible disclosure policy, or bug bounty program." The scope, bounty table and submission state could not be read anonymously and are therefore not asserted here. security_txt: served: false probed_hosts: [sofi.com, www.sofi.com, api.sofi.com, tech.sofi.com, docs.tech.sofi.com, docs.sofi.com, sandbox.gpsrv.com] result: >- 404 on every host except docs.tech.sofi.com and docs.sofi.com, which answer 200 with a ReadMe single-page-app HTML shell rather than a document. No RFC 9116 security.txt exists. see: well-known/sofi-technologies-well-known.yml gap: >- SoFi runs a real disclosure program and publishes no pointer to it from any of its own hosts. A single /.well-known/security.txt on sofi.com naming the HackerOne URL would close this. probes: - { url: 'https://hackerone.com/sofi-1', status: 200, note: 'JS shell; program confirmed via the page meta description' } - { url: 'https://hackerone.com/sofi-1?type=team', status: 200, content_type: 'application/json', note: 'team JSON: id 76924, name Sofi, website https://www.sofi.com/' } - { url: 'https://www.sofi.com/responsible-disclosure/', status: 404 } - { url: 'https://www.sofi.com/security/', status: 404 } - { url: 'https://tech.sofi.com/security/', status: 404 } - { url: 'https://www.sofi.com/.well-known/security.txt', status: 404 } maintainers: - FN: Kin Lane email: kin@apievangelist.com