Findigs · Vulnerability Disclosure

Findigs Vulnerability Disclosure

Vulnerability disclosure

Findigs runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

rental-screeningtenant-screeningresident-screeningrental-applicationunderwritingdecisioningidentity-verificationincome-verificationcredit-checkbackground-checkfraud-detectionproperty-managementreal-estateproptechfcrafair-housingwebhooks
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@findigs.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-12'
method: searched
probe: true
source: https://www.findigs.com/legal/responsible-disclosure-policy
policy:
- https://www.findigs.com/legal/responsible-disclosure-policy
contact:
- security@findigs.com
bug_bounty: false
bug_bounty_platform: null
safe_harbor: partial
program:
  name: Findigs Responsible Disclosure Policy
  reporting_channel: email
  reporting_address: security@findigs.com
  disclosure_expectation: >-
    Researchers are asked to give Findigs a reasonable amount of time to resolve the issue before
    disclosing it publicly or to a third party, and to interact only with accounts they own or have
    explicit permission to test.
  conduct_requirements:
  - Avoid violating privacy, destroying data, or interrupting or degrading the Findigs service.
  out_of_scope:
  - Distributed Denial of Service (DDoS) attacks
  - Spamming
  - Social engineering or phishing targeting Findigs employees
  - Attacks against physical property or data centers
  response_commitment: Findigs states it will respond as soon as possible.
evidence:
- {source: 'https://www.findigs.com/legal/responsible-disclosure-policy', kind: disclosure-policy-page, http_status: 200}
- {source: 'dig CAA findigs.com', kind: caa-iodef, value: '0 iodef "mailto:security@findigs.com"'}
- {source: 'https://www.findigs.com/legal/information-security-addendum', kind: information-security-program, http_status: 200}
note: >-
  Findigs serves NO RFC 9116 /.well-known/security.txt on any host (see
  well-known/findigs-well-known.yml — 404 everywhere). The disclosure program exists only as an HTML
  legal page. The security contact is independently corroborated out-of-band by the findigs.com CAA
  iodef record, which names the same mailbox. No bug bounty program on HackerOne, Bugcrowd or
  Intigriti was found. The separate Information Security Addendum
  (https://www.findigs.com/legal/information-security-addendum) describes an internal security program
  — periodic risk assessments, firewall/antivirus/patch management/intrusion detection, and at least
  annual review of safeguard effectiveness — but names no third-party certification.