Bonneville Power Administration · Vulnerability Disclosure

Bonneville Power Administration Vulnerability Disclosure

Vulnerability disclosure

BPA does publish a route to report a vulnerability, but not one of its own and not at the machine-readable address. Every page of bpa.gov carries a footer link labelled "Vulnerability Disclosure Policy" pointing at the Department of Energy's VDP — BPA is a DOE power marketing administration, so DOE's policy is the governing one. There is no security.txt on any BPA host.

Bonneville Power Administration runs a coordinated vulnerability disclosure program on Hackerone.

EnergyFederal-GovernmentGISHydroelectricPacific NorthwestPowerTransmissionWind
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-06'
method: searched
source: >-
  the "Vulnerability Disclosure Policy" link in the bpa.gov site footer, followed to
  https://www.energy.gov/cio/articles/vulnerability-disclosure-policy
provider: Bonneville Power Administration
providerId: bonneville-power-administration
description: >-
  BPA does publish a route to report a vulnerability, but not one of its own and not at
  the machine-readable address. Every page of bpa.gov carries a footer link labelled
  "Vulnerability Disclosure Policy" pointing at the Department of Energy's VDP — BPA is a
  DOE power marketing administration, so DOE's policy is the governing one. There is no
  security.txt on any BPA host.
program:
  published: true
  scope: department-level
  first_party: false
  policy_url: https://www.energy.gov/cio/articles/vulnerability-disclosure-policy
  policy_owner: U.S. Department of Energy, Office of the Chief Information Officer
  linked_from: https://www.bpa.gov/ (site footer, present on every page)
  bug_bounty: false
  paid: false
  safe_harbor: stated in the DOE policy
reporting_channels:
- type: portal
  url: https://doe.responsibledisclosure.com
  http_status: 403
  note: >-
    The DOE policy names this as the primary submission portal. It returned 403 to our
    client on 2026-09-06 — an edge/bot policy, not evidence the portal is gone; recorded
    with the status observed rather than judged dead.
- type: email
  value: DOEOCIOInfo@hq.doe.gov
  source: stated in the DOE vulnerability disclosure policy
- type: phone
  value: (202) 586-0166
  source: stated in the DOE vulnerability disclosure policy
scope_caveat: >-
  The DOE policy uses a progressive scope model — at issuance at least one DOE public
  internet-accessible system is in scope, expanding on a schedule until all DOE-produced
  public-facing systems are covered. It names no agency and does not mention BPA or
  bpa.gov explicitly. A reporter therefore cannot confirm from the policy text alone that
  a given BPA system is in scope; BPA's own footer link is the assertion that it applies.
gaps:
- id: no-security-txt
  detail: >-
    No /.well-known/security.txt on bpa.gov, www.bpa.gov, transmission.bpa.gov or
    data-bpagis.hub.arcgis.com. An RFC 9116 file pointing at the DOE policy and contact
    would cost BPA nothing and make the route machine-discoverable.
  evidence:
  - url: https://www.bpa.gov/.well-known/security.txt
    http_status: 404
  - url: https://bpa.gov/.well-known/security.txt
    http_status: 404
  - url: https://transmission.bpa.gov/.well-known/security.txt
    http_status: 200
    note: HTML site shell, not RFC 9116 text — the host answers 200 for every /.well-known/ path.
  - url: https://data-bpagis.hub.arcgis.com/.well-known/security.txt
    http_status: 404
- id: no-bpa-specific-policy
  detail: >-
    No BPA-authored disclosure policy, scope statement or acknowledgements page. Reports
    about BPA systems go to a department-wide channel.
- id: no-bug-bounty
  detail: >-
    No HackerOne, Bugcrowd or Intigriti program was found for BPA or for DOE. Searched
    2026-09-06.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bonneville-power-administration-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.