Hydro-Québec · Vulnerability Disclosure

Hydro Quebec Vulnerability Disclosure

Vulnerability disclosure

Hydro-Québec runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyCanadaUtilitiesElectricityGridEnergy MarketsRenewablesOpen DataDemand ResponseCarbon
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@opendatasoft.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://donnees.hydroquebec.com/.well-known/security.txt (HTTP 200, fetched 2026-07-27)
note: >-
  The mechanical probe pass found nothing because it checked hydroquebec.com, which answers every
  unknown path with an HTTP 200 soft-404 HTML page. Probing the API host directly did return a real
  RFC 9116 document. Important caveat: that security.txt is served by Opendatasoft, the platform
  vendor hosting donnees.hydroquebec.com, and names an Opendatasoft security contact — it is the
  disclosure route for the platform serving the API, not a Hydro-Québec-authored programme.
  Hydro-Québec itself publishes no security.txt, no bug bounty and no responsible-disclosure page.
policy: []
contact:
- mailto:security@opendatasoft.com
security_txt:
  url: https://donnees.hydroquebec.com/.well-known/security.txt
  status: 200
  file: well-known/hydro-quebec-security.txt
  rfc: RFC 9116
  fields:
    Contact: mailto:security@opendatasoft.com
    Expires: '2050-01-01T11:00:00.000Z'
    Preferred-Languages: en,fr
  authored_by: opendatasoft (platform vendor)
  expires_note: >-
    An Expires value of 2050-01-01 far exceeds the RFC 9116 recommendation that the value be less
    than a year in the future.
bug_bounty:
  program: null
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti programme found for Hydro-Québec.
disclosure_pages_probed:
- {url: 'https://www.hydroquebec.com/.well-known/security.txt', status: 200, present: false, note: soft-404 HTML}
- {url: 'https://www.hydroquebec.com/security/', status: 200, present: false, note: soft-404 HTML}
- {url: 'https://www.hydroquebec.com/responsible-disclosure/', status: 200, present: false, note: soft-404 HTML}
- {url: 'https://donnees.hydroquebec.com/.well-known/security.txt', status: 200, present: true}
alternate_contact:
  name: Hydro-Québec Open Data team
  url: https://www.hydroquebec.com/sefco2016/en/open-data-contact-us.html
  status: 200
  verified: '2026-07-27'
  note: >-
    A general contact form for the open data programme, not a security channel. Recorded because it
    is the only Hydro-Québec-operated route to the people who run this API.
evidence:
- {source: 'https://donnees.hydroquebec.com/.well-known/security.txt', kind: security.txt, status: 200}
- {source: well-known/hydro-quebec-security.txt, kind: saved verbatim}
gaps:
- Hydro-Québec publishes no vulnerability disclosure policy of its own.
- No security.txt on the corporate domain.
- No named coordinated-disclosure timeline, safe-harbour statement or PGP key.