Equifax Vulnerability Disclosure
Equifax runs a Vulnerability Disclosure Program on HackerOne. It is linked from the footer of equifax.com itself — the "Report a Vulnerability" link on https://www.equifax.com/about-equifax/security/ resolves to https://hackerone.com/equifax/ — so the program is first-party and discoverable from Equifax's own surface. The automated probe recorded nothing because Equifax serves no /.well-known/security.txt on any host (every path 404s; see well-known/equifax-well-known.yml); the disclosure route is published as an ordinary site link instead of an RFC 9116 document.
Equifax runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.