10x Banking Technology Services · Vulnerability Disclosure

10X Banking Technology Services Vulnerability Disclosure

Vulnerability disclosure

10x Banking runs a published, non-monetary responsible disclosure programme with a dedicated intake address and explicit safe-harbour language. It is a policy, not a bug bounty, and it is not run through a platform (no HackerOne, Bugcrowd or Intigriti presence was found).

10x Banking Technology Services runs a coordinated vulnerability disclosure program on Hackerone.

Financial-ServicesBankingCore BankingCloud NativeBanking as a ServiceEmbedded FinancePaymentsLendingDepositsCardsEvent DrivenUnited KingdomSaaSFintech
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-05'
method: searched
source: >-
  https://www.10xbanking.com/responsible-disclosure (HTTP 200) and the served
  https://www.10xbanking.com/.well-known/security.txt (HTTP 200, application/rtf).
description: >-
  10x Banking runs a published, non-monetary responsible disclosure programme with
  a dedicated intake address and explicit safe-harbour language. It is a policy,
  not a bug bounty, and it is not run through a platform (no HackerOne, Bugcrowd
  or Intigriti presence was found).

program:
  type: responsible-disclosure-policy
  bug_bounty: false
  platform: none
  policy_url: https://www.10xbanking.com/responsible-disclosure
  policy_status: 200
  contact: mailto:security-disclosures@10xbanking.com
  preferred_languages: en

security_txt:
  url: https://www.10xbanking.com/.well-known/security.txt
  status: 200
  file: ../well-known/10x-banking-technology-services-security.txt
  content_type: application/rtf
  signed: false
  fields:
    Contact: mailto:security-disclosures@10xbanking.com
    Expires: '2025-01-30T23:00:00.000Z'
    Preferred-Languages: en
    Hiring: https://www.10xbanking.com/job-vacancies
  defects:
    - >-
      Expired: the Expires field is 2025-01-30, more than a year before this probe.
      RFC 9116 says a consumer should not trust a security.txt past its Expires date.
    - >-
      Served as application/rtf with RTF control words in the body rather than the
      RFC 9116 required text/plain, so a parser reads control markup, not fields.
    - >-
      No Policy field, even though a policy page exists at
      https://www.10xbanking.com/responsible-disclosure.
    - No Encryption field and no detached OpenPGP signature.

scope:
  in_scope: >-
    "all of 10x Banking's digital assets, including but not limited to websites,
    web applications, mobile applications, APIs, and any other services operated
    and owned by 10x Banking"
  out_of_scope: >-
    The 10xbanking.com marketing website itself — the policy states it "is considered
    hosted by a third party and is not in scope without explicit permission".

safe_harbour:
  offered: true
  text: >-
    "10x Banking will not pursue legal action against individuals who report security
    vulnerabilities in accordance with this Responsible Disclosure Policy, provided
    they do so in good faith and comply with the guidelines outlined here"

rewards:
  monetary: false
  text: >-
    "We do not, as a matter of course, offer monetary rewards for vulnerability
    reports" — recognition may be offered at 10x's discretion for valid, serious
    findings.

notes:
  - >-
    No trust centre, no SOC 2 / ISO 27001 / PCI DSS certification page and no
    compliance portal were found on any 10x host or via search, so no Compliance
    pointer is claimed. For a core banking vendor serving Chase UK and Westpac these
    attestations almost certainly exist; they are simply not published to the open web.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/10x-banking-technology-services-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.