Ather Energy · Vulnerability Disclosure

Ather Energy Vulnerability Disclosure

Vulnerability disclosure

Ather Energy runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyElectric VehiclesAutomotiveTransportationManufacturingEnergyEV ChargingMobilityInternet of ThingsIndia
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
https://www.atherenergy.com/contact/bug-bounty

Source

Vulnerability Disclosure

ather-energy-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-31'
method: searched
probe: true
program:
  name: Responsible Vulnerability Disclosure Program (RVDP)
  operator: Ather Energy Limited
  self_hosted: true
  platform: null
  note: >-
    Ather runs its own program directly — no HackerOne, Bugcrowd or Intigriti
    listing was found. Reports are submitted by email to the Ather security team with
    the subject line "Bug Bounty", or through the dedicated contact form. The program
    is open to individuals only, not organisations.
policy:
- https://www.atherenergy.com/bug-bounty
- https://www.atherenergy.com/bug-bounty-terms
contact:
- https://www.atherenergy.com/contact/bug-bounty
rewards: true
safe_harbor_documented: true
requirements:
- Adherence to Ather's Responsible Disclosure & Reporting Guidelines is mandatory.
- Do not run tests that may disrupt Ather applications or services.
- Demonstrate impact in a secure manner that protects sensitive data and user privacy.
- On discovering exposure of non-public or personally identifiable information, stop
  testing and notify Ather immediately.
- Purge any stored non-public or PII data upon reporting a vulnerability.
- Open to individuals only, not to organisations.
security_txt:
  present: false
  probed: https://www.atherenergy.com/.well-known/security.txt
  status: 404
  gap: >-
    Ather publishes a real disclosure program but does not advertise it at the RFC 9116
    /.well-known/security.txt location, so automated discovery misses it.
evidence:
- source: https://www.atherenergy.com/sitemap.xml
  kind: provider-sitemap
  note: /bug-bounty, /bug-bounty-terms and /contact/bug-bounty are all listed in Ather's own sitemap
- source: https://www.atherenergy.com/bug-bounty
  kind: disclosure-page
  title: Responsible Vulnerability Disclosure Program | Ather Energy
- source: https://www.atherenergy.com/bug-bounty-terms
  kind: program-terms
  title: Bug Bounty Terms And Conditions | Ather Energy
- source: https://www.atherenergy.com/contact/bug-bounty
  kind: report-intake
  title: Contact Us | Ather Energy in Bug Bounty
  http_status: 200
x-evidence:
  fetched: '2026-07-31'
  http_status: 403
  note: >-
    Ather's HTML pages sit behind Cloudflare bot protection and return 403 to
    non-browser clients (verified with browser-equivalent headers), so page bodies
    could not be captured verbatim. Existence and titles are confirmed from Ather's
    own published sitemap.xml (HTTP 200) plus indexed page titles; /contact/bug-bounty
    returns HTTP 200 to a plain HEAD. Nothing here is inferred beyond what Ather
    itself publishes.