Bharti Airtel · Vulnerability Disclosure

Bharti Airtel Vulnerability Disclosure

Vulnerability disclosure

Bharti Airtel runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

TelecommunicationsIndiaMobile Network OperatorNetwork APIsCAMARAOpen GatewaySIM SwapCPaaSMessagingSMSRCSVoiceIoTM2MDevice LocationBroadband5GIdentity VerificationCarrier BillingConsent Management
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: probed
probe: true
result: none
policy: []
contact: []
bug_bounty:
  present: false
  platforms_checked:
    - HackerOne
    - Bugcrowd
    - Intigriti
finding: >-
  No coordinated vulnerability disclosure policy, security contact or bug bounty programme is
  published on any anonymously reachable Bharti Airtel host. This is a verified negative from
  0-working/probe-security-programs.py plus additional manual probing, not an unchecked gap.
evidence:
  - source: https://www.airtel.in/.well-known/security.txt
    status: 404
    kind: security.txt
  - source: https://openapi.airtel.in/.well-known/security.txt
    status: 404
    kind: security.txt
  - source: https://m2m.airteliot.co.in/.well-known/security.txt
    status: 404
    kind: security.txt
  - source: https://www.airtel.in/security.txt
    status: 200
    kind: soft-404
    note: >-
      Returns text/html, 9,787 bytes — the airtel.in Angular SPA shell with the consumer homepage
      title. Not an RFC 9116 document.
  - source: https://www.airtel.in/responsible-disclosure
    status: 200
    kind: soft-404
    note: 8,991-byte SPA shell, byte-identical to /security, /vulnerability-disclosure and /about-bharti/security.
  - source: https://www.airtel.in/security
    status: 200
    kind: soft-404
  - source: https://www.airtel.in/vulnerability-disclosure
    status: 200
    kind: soft-404
  - source: https://www.airtel.in/about-bharti/security
    status: 200
    kind: soft-404
note: >-
  No `Security` pointer is emitted in apis.yml for this provider — there is no disclosure page or
  security policy to point at. Airtel does publish product-side API security (the Airtel WAAP
  offering at https://www.airtel.in/b2b/waap is a Web Application and API Protection product it
  SELLS), which is not the same thing as a disclosure programme for its own APIs and is not
  recorded as one.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bharti-airtel-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.