Lloyd's of London · Vulnerability Disclosure
Lloyds Of London Vulnerability Disclosure
Vulnerability disclosure
Lloyd's runs a real, named Responsible Disclosure Programme. It publishes an RFC 9116 security.txt at the apex of its web estate with a working reporting mailbox, and a live hall-of-fame page crediting named researchers. There is no paid bug bounty and no third-party platform (HackerOne / Bugcrowd / Intigriti); the intake is a direct mailbox and the programme is deliberately low-friction - the security.txt comments explicitly decline to publish a PGP key "because we want to keep the route for reporting as open as possible".
Lloyd’s of London runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
InsuranceUnited KingdomReinsuranceSpecialty InsuranceLondon MarketUnderwritingClaimsDelegated AuthorityBrokerMarket InfrastructureStandardsACORD
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
mailto:securityreporting@lloyds.com