Bupa · Vulnerability Disclosure

Bupa Vulnerability Disclosure

Vulnerability disclosure

Bupa runs a coordinated vulnerability disclosure program on Hackerone.

InsuranceUnited KingdomHealth InsuranceLife and HealthCarrierHealthcareAged CareClaimsPolicy AdministrationPartner Gated
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

bupa-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
source: https://bugcrowd.com/engagements/bupa-aus-vdp-pro
program:
  name: Bupa Australia Vulnerability Disclosure Engagement
  type: vulnerability-disclosure
  platform: Bugcrowd
  url: https://bugcrowd.com/engagements/bupa-aus-vdp-pro
  http_status: 200
  managed_by: Bupa Australia Pty Limited
  bounty: false
  note: >-
    Bugcrowd classifies the engagement as "Vulnerability Disclosure", not a
    paid bug bounty. The public engagement page renders its brief (scope,
    safe-harbour text, submission form) client-side behind the Bugcrowd
    researcher experience, so the scope list and reward table could not be read
    anonymously and are deliberately not reproduced here.
policy:
- https://bugcrowd.com/engagements/bupa-aus-vdp-pro
contact: []
security_txt:
  published: false
  note: >-
    No RFC 9116 security.txt is served on any Bupa host. /.well-known/
    security.txt returns 404 on www.bupa.com, bupa.com, portal.api.bupa.com.au,
    www.bupa.com.au, www.bupa.co.uk and bupaglobal.com; 502 on api.bupa.com.au;
    and an HTML SPA shell / block page (not a text/plain policy) on
    apidoc.bupa.cl and api.bupa.cl. See well-known/bupa-well-known.yml.
evidence:
- source: https://bugcrowd.com/engagements/bupa-aus-vdp-pro
  kind: bug-bounty-platform-page
  fetched: '2026-07-25'
  http_status: 200
  detail: >-
    Page title "Vulnerability Disclosure: Bupa Australia Vulnerability
    Disclosure Engagement - Bugcrowd".
- source: https://www.bupa.com/impact/responsible-business/business-ethics/managing-cybersecurity-risks
  kind: corporate-security-governance-page
  fetched: '2026-07-25'
  http_status: 200
  detail: >-
    Group-level cybersecurity page. Describes a "Bupa-wide Enterprise Policy on
    Information Security and related Standards", a three-lines-of-defence risk
    model, oversight by the Bupa Enterprise Risk Committee and Board Risk
    Committee, and "accredited cybersecurity experts for independent
    assessments". It names no certification and does not reference a
    vulnerability disclosure programme or a security contact address.
not_found:
- what: HackerOne programme
  detail: >-
    https://hackerone.com/bupa returns HTTP 200 but serves the generic
    HackerOne single-page shell (title "HackerOne") with no Bupa programme
    payload; no HackerOne programme for Bupa could be confirmed.
- what: group-level responsible disclosure page
  detail: >-
    /security, /responsible-disclosure and /vulnerability-disclosure all return
    404 on www.bupa.com; on www.bupa.com.au they return HTTP 200 soft-404s
    (page title "404", canonical https://www.bupa.com.au/404); www.bupa.co.uk
    returns 403 to automated clients.