Lloyd's of London · Vulnerability Disclosure

Lloyds Of London Vulnerability Disclosure

Vulnerability disclosure

Lloyd's runs a real, named Responsible Disclosure Programme. It publishes an RFC 9116 security.txt at the apex of its web estate with a working reporting mailbox, and a live hall-of-fame page crediting named researchers. There is no paid bug bounty and no third-party platform (HackerOne / Bugcrowd / Intigriti); the intake is a direct mailbox and the programme is deliberately low-friction - the security.txt comments explicitly decline to publish a PGP key "because we want to keep the route for reporting as open as possible".

Lloyd’s of London runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

InsuranceUnited KingdomReinsuranceSpecialty InsuranceLondon MarketUnderwritingClaimsDelegated AuthorityBrokerMarket InfrastructureStandardsACORD
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:securityreporting@lloyds.com

Source

Vulnerability Disclosure

lloyds-of-london-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
source: https://www.lloyds.com/.well-known/security.txt
description: >-
  Lloyd's runs a real, named Responsible Disclosure Programme. It publishes an RFC 9116
  security.txt at the apex of its web estate with a working reporting mailbox, and a live
  hall-of-fame page crediting named researchers. There is no paid bug bounty and no third-party
  platform (HackerOne / Bugcrowd / Intigriti); the intake is a direct mailbox and the programme is
  deliberately low-friction - the security.txt comments explicitly decline to publish a PGP key
  "because we want to keep the route for reporting as open as possible".
programme:
  name: Responsible Disclosure Programme
  operator: Corporation of Lloyd's
  bug_bounty: false
  platform: null
  safe_harbour_published: false
policy:
- https://www.lloyds.com/security-reports
contact:
- mailto:securityreporting@lloyds.com
acknowledgments:
  url: https://www.lloyds.com/security-reports
  live: true
  status: 200
  note: >-
    The security.txt carries the Acknowledgments line COMMENTED OUT with the annotation
    "(Program coming soon!)", but the page itself is now live and publishes a hall of fame. The
    security.txt has not been updated to uncomment it.
preferred_languages: [en]
canonical: https://www.lloyds.com/.well-known/security.txt
encryption: null
expires: null
evidence:
- source: https://www.lloyds.com/.well-known/security.txt
  kind: security.txt (live probe 2026-07-25)
  status: 200
  file: well-known/lloyds-of-london-security.txt
  fields: [Contact, Preferred-Languages, Canonical]
- source: https://www.lloyds.com/security-reports
  kind: acknowledgments / hall of fame (live probe 2026-07-25)
  status: 200
  quote: >-
    "Responsible Disclosure Programme - We would like to thank all persons who make a responsible
    disclosure to us and recognise their valuable contribution in increasing the security of our
    products and services for our benefit and for the benefit of our customers by featuring those
    contributors in our hall of fame."
gaps:
- The security.txt publishes no Expires field, which RFC 9116 section 2.5.5 requires; parsers
  should treat the file as stale.
- No Policy field is declared in the security.txt itself (the disclosure page is only referenced
  from a commented-out Acknowledgments line).
- No Encryption key and no published safe-harbour / legal-protection statement for researchers.
- The London Market API Gateway hosts (api / preprod-api / sand-api .londonmarketgroup.co.uk)
  publish no security.txt of their own - the API estate is not covered by a disclosure route on
  its own domain.
related:
- well-known/lloyds-of-london-well-known.yml
- security/lloyds-of-london-domain-security.yml