Flix · Vulnerability Disclosure

Flix Vulnerability Disclosure

Vulnerability disclosure

Flix runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyConsumerTransportationMobilityTravelBusTrainGround Transportation
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:responsible-disclosure@flixbus.com

Source

Vulnerability Disclosure

flix-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: true
policy:
- https://global.flixbus.com/responsible-disclosure
contact:
- mailto:responsible-disclosure@flixbus.com
encryption: https://responsible-disclosure.security.flix.tech/pgp.txt
preferred_languages: [de, en]
security_txt: well-known/flix-security.txt
security_txt_expires: '2027-05-04T00:00:00Z'
bug_bounty: false
bug_bounty_note: >-
  Flix runs a self-managed coordinated vulnerability-disclosure program and does
  not currently offer bug bounties or other compensation. Reports are handled
  directly by email (no HackerOne/Bugcrowd/Intigriti platform).
scope: >-
  All FlixBus digital products, including mobile applications and web services.
disclosure_terms: >-
  Researchers are asked to give Flix reasonable time to investigate and remediate
  before publishing findings; Flix commits to publishing security advisories
  (vulnerability description, affected versions, severity, guidance) upon fix.
evidence:
- {source: well-known/flix-security.txt, kind: security.txt}
- {source: https://global.flixbus.com/responsible-disclosure, kind: disclosure-page}