generated: '2026-09-13' method: searched probe: true source: well-known/visma-connect-security.txt note: 'The automated probe recorded nothing because it checks the apex domain: visma.com and www.visma.com serve no security.txt (HTTP 404). Visma publishes its canonical security.txt on its identity host, https://connect.visma.com/.well-known/security.txt, which returned HTTP 200 on 2026-09-13 and declares itself canonical at that URL.' security_txt: url: https://connect.visma.com/.well-known/security.txt status: 200 canonical: https://connect.visma.com/.well-known/security.txt expires: '2029-12-31T23:00:00.000Z' file: well-known/visma-connect-security.txt policy: - https://www.visma.com/trust-centre/security/products-and-services/bug-bounty-and-responsible-disclosure/ - https://app.intigriti.com/programs/visma/visma/detail contact: - mailto:security@visma.com - https://www.visma.com/trust-centre/security/products-and-services/bug-bounty-and-responsible-disclosure/ - https://app.intigriti.com/programs/visma/visma/detail encryption: https://www.visma.com/trust-centre/security/products-and-services/bug-bounty-and-responsible-disclosure/ acknowledgments: - https://www.visma.com/trust-centre/security/products-and-services/bug-bounty-and-responsible-disclosure/hall-of-fame/ - https://app.intigriti.com/programs/visma/visma/leaderboard?alltime=true hiring: https://www.visma.com/careers bug_bounty: platform: Intigriti programs: - name: Responsible Disclosure Program scope: All Visma services, products and web properties rewards: Swag for valid Medium+ severity reports hall_of_fame: true - name: Public Bug Bounty Program scope: A named subset of Visma assets listed in the programme rewards: Monetary bounties, limited to the assets listed in this programme safe_harbor: true safe_harbor_text: '"When conducting vulnerability research according to this policy, we consider this research to be authorized, lawful, helpful to the overall security of the Internet, and conducted in good faith."' out_of_scope: - Theoretical vulnerabilities without proof - Automated tool output without a proof of concept - Issues requiring man-in-the-middle - Weak HTTP headers - Non-sensitive data exposure - Clickjacking - Denial of service internal_security_engineering: github_org: https://github.com/visma-prodsec note: Visma Product Security publishes its own tooling openly (confused, ConfusedDotnet, columbo, BugBountySelfServicePortal). evidence: - url: https://connect.visma.com/.well-known/security.txt status: 200 - url: https://www.visma.com/.well-known/security.txt status: 404 - url: https://www.visma.com/trust-centre/security/products-and-services/bug-bounty-and-responsible-disclosure/ status: 200