Aldermore Bank · Vulnerability Disclosure

Aldermore Vulnerability Disclosure

Vulnerability disclosure

Aldermore Bank runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Financial ServicesBankingSavingsSpecialist LendingOpen BankingPSD2OBIEUnited KingdomPaymentsAccount Information
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
securityresearch@aldermore.co.uk

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-23'
method: searched
probe: true
source: https://www.aldermore.co.uk/.well-known/security.txt
policy: []
contact:
  - securityresearch@aldermore.co.uk
expires: '2027-01-31T00:00:00.000Z'
notes: >-
  Aldermore Bank publishes an RFC 9116 security.txt at
  https://www.aldermore.co.uk/.well-known/security.txt directing security
  researchers to securityresearch@aldermore.co.uk. The file asks reporters not to
  include sensitive information in the initial email; a secure communication channel
  is provided in the reply. No public bug-bounty program (HackerOne/Bugcrowd/Intigriti)
  or standalone responsible-disclosure page was found. Note: the security.txt fields
  are comment-prefixed (each line begins with '#'), so strict RFC 9116 parsers may
  not extract Contact/Expires automatically, though the intent is unambiguous.
evidence:
  - source: well-known/aldermore-security.txt
    kind: security.txt
    contact: securityresearch@aldermore.co.uk