FIS Global · Vulnerability Disclosure

Fis Vulnerability Disclosure

Vulnerability disclosure

FIS Global runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

BankingCore BankingFinancial ServicesPaymentsFintech
Program: Bugcrowd

Disclosure Policy

Policy
Policy
Policy
Policy

Security Contact

Contact
email
Contact
notesecurity.txt gives a web form (the responsible-disclosure page) rather than an email address.

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-10'
method: probed
source: https://fisglobal.com/.well-known/security.txt
program:
  exists: true
  type: bug-bounty
  platform: Bugcrowd
  name: 'Bug Bounty: FIS'
  url: https://bugcrowd.com/engagements/fis
  http_status: 200
  managed: true
policy:
  url: https://www.fisglobal.com/en/responsible-disclosure
  title: Vulnerability Disclosure
  http_status: 200
  note: >-
    Reachable in a browser; the page is server-rendered behind Akamai bot management and resets
    the connection for a plain crawler, so it was confirmed through a rendering fetch rather
    than curl. Per the enrichment contract a bot challenge is not a dead pointer.
security_txt:
  url: https://fisglobal.com/.well-known/security.txt
  http_status: 200
  file: ../well-known/fis-security.txt
  rfc: RFC 9116
  fields:
    Contact: https://www.fisglobal.com/en/responsible-disclosure
    Expires: '2023-12-31T18:00:00.000Z'
    Acknowledgments: https://bugcrowd.com/fis/hall-of-fame
    Preferred-Languages: en
    Policy: https://www.fisglobal.com/en/responsible-disclosure
    Hiring: https://careers.fisglobal.com/
  deviations:
  - id: expired
    detail: The Expires field lapsed on 2023-12-31; RFC 9116 says clients should consider the file stale after that date. The document is still served unchanged as of 2026-09-10.
  - id: content-type
    detail: Served as text/html (the edge wraps the plain-text body in <pre>), not the text/plain required by RFC 9116 §3.
  served_on:
  - fisglobal.com
  - developer.fisglobal.com
  - api-dev-uat.fisglobal.com
  - api-gw-ui-uat.fisglobal.com
acknowledgments:
  hall_of_fame: https://bugcrowd.com/fis/hall-of-fame
contact:
  email: null
  note: security.txt gives a web form (the responsible-disclosure page) rather than an email address.
evidence:
- url: https://fisglobal.com/.well-known/security.txt
  status: 200
  fetched: '2026-09-10'
- url: https://bugcrowd.com/engagements/fis
  status: 200
  fetched: '2026-09-10'
- url: https://www.fisglobal.com/en/responsible-disclosure
  status: 200
  fetched: '2026-09-10'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fis-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.