Lloyds Of London Vulnerability Disclosure
Lloyd's runs a real, named Responsible Disclosure Programme. It publishes an RFC 9116 security.txt at the apex of its web estate with a working reporting mailbox, and a live hall-of-fame page crediting named researchers. There is no paid bug bounty and no third-party platform (HackerOne / Bugcrowd / Intigriti); the intake is a direct mailbox and the programme is deliberately low-friction - the security.txt comments explicitly decline to publish a PGP key "because we want to keep the route for reporting as open as possible".
Lloyd’s of London runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.