Fintech Farm · Vulnerability Disclosure

Fintech Farm Vulnerability Disclosure

Vulnerability disclosure

Fintech Farm runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyBankingFinancial ServicesNeobankDigital BankingFintechCreditEmerging MarketsBanking as a ServiceMobile Banking
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@fintech-farm.com
Contact
https://www.fintech-farm.com/security

Source

Vulnerability Disclosure

fintech-farm-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-12'
method: searched
probe: true
source: https://www.fintech-farm.com/security
docs: https://www.fintech-farm.com/security
program:
  type: vulnerability-disclosure-policy
  bounty: false
  bounty_note: >-
    No monetary reward or bug bounty is offered; the page describes a
    coordinated-disclosure program only. Not hosted on HackerOne, Bugcrowd or
    Intigriti — Fintech Farm runs it directly over email.
  platform: self-hosted
security_txt:
  present: true
  standard: RFC 9116
  url: https://www.fintech-farm.com/.well-known/security.txt
  file: well-known/fintech-farm-security.txt
  http_status: 200
  content_type: text/plain
  expires: '2027-06-13T23:59:59.000Z'
  canonical: https://fintech-farm.com/.well-known/security.txt
  preferred_languages:
  - en
  - uk
  - ru
policy:
- https://www.fintech-farm.com/security
contact:
- mailto:security@fintech-farm.com
- https://www.fintech-farm.com/security
contact_hours: Mon-Fri, 09:00-18:00 UTC+2
encryption:
  pgp_key: null
  note: >-
    No PGP key is published. The policy asks researchers who need to send
    encrypted material to email first so a secure channel can be arranged.
sla:
- stage: acknowledgement
  target: 5 business days
- stage: initial assessment
  target: 10 business days
- stage: coordinated disclosure
  target: 90 days
scope:
  in_scope:
  - mobile applications
  - web applications
  - public APIs
  - backend services
  - SDKs and integration libraries
  - authentication infrastructure
  out_of_scope:
  - third-party services
  - denial-of-service testing
  - social engineering
  - physical attacks
  - theoretical issues without a practical proof of concept
report_requirements:
- the affected product, URL or API and where it was discovered
- reproduction steps and demonstrated impact
- proof-of-concept material, samples or screenshots
- attribution preference
safe_harbor:
  offered: true
  text: >-
    We will not pursue or support legal action against security researchers who
    discover and report vulnerabilities in good faith and in accordance with
    this policy.
advisories:
  published: false
  note: >-
    The page states no security advisories are currently published; interim
    mitigation guidance is given on the page itself.
note: >-
  Notable finding: Fintech Farm publishes no developer program and no public
  API contract, yet its disclosure policy explicitly names "public APIs" and
  "SDKs and integration libraries" as in scope. The integration surface exists
  and is described as public in the security policy, but it is not documented
  anywhere a member of the public can reach.
evidence:
- source: https://www.fintech-farm.com/.well-known/security.txt
  kind: security.txt (live probe)
  http_status: 200
- source: https://www.fintech-farm.com/security
  kind: published vulnerability disclosure policy page
  http_status: 200