Reliance Jio · Vulnerability Disclosure

Reliance Jio Vulnerability Disclosure

Vulnerability disclosure

Reliance Jio runs a responsible-disclosure programme and a bug bounty, but the only machine-discoverable evidence of it in the whole estate is a single RFC 9116 security.txt served from jiomeetpro.jio.com - the JioMeet API host. There is no security.txt on www.jio.com (the SPA answers 200 text/html for every /.well-known/ path, including invented ones), none on developer.jio.com, dev.jiomeet.com or platform.jiomeet.com, and no /security or /responsible-disclosure page on jio.com (both redirect to page-not-found.html). No HackerOne, Bugcrowd or Intigriti programme page was found.

Reliance Jio runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

TelecommunicationsIndiaMobile Network OperatorNetwork APIsCAMARAOpen GatewaySIM SwapIdentity VerificationCPaaSMessagingVoiceIoTBroadband5GBSSOSSStandardsVideo Conferencing
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:jio.bugsreporting@jio.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
description: >-
  Reliance Jio runs a responsible-disclosure programme and a bug bounty, but the only
  machine-discoverable evidence of it in the whole estate is a single RFC 9116
  security.txt served from jiomeetpro.jio.com - the JioMeet API host. There is no
  security.txt on www.jio.com (the SPA answers 200 text/html for every /.well-known/
  path, including invented ones), none on developer.jio.com, dev.jiomeet.com or
  platform.jiomeet.com, and no /security or /responsible-disclosure page on jio.com
  (both redirect to page-not-found.html). No HackerOne, Bugcrowd or Intigriti programme
  page was found.
contact:
  - mailto:jio.bugsreporting@jio.com
policy: []
bug_bounty:
  advertised: true
  platform: null
  note: >-
    The security.txt states "Based on the impact and severity of the reported bug you
    may also become eligible for a reward under our Bug Bounty Program." No programme
    page, scope document or public platform listing was found - the reward programme is
    referenced but not published.
security_txt:
  url: https://jiomeetpro.jio.com/.well-known/security.txt
  status: 200
  file: well-known/reliance-jio-security.txt
  rfc9116_fields_present: [Contact]
  rfc9116_fields_missing: [Expires, Policy, Preferred-Languages, Encryption, Canonical]
  note: >-
    Contact is the only real RFC 9116 field; everything else in the file is comment
    lines. Expires is required by RFC 9116 and absent.
evidence:
  - source: https://jiomeetpro.jio.com/.well-known/security.txt
    kind: security.txt
    status: 200
    quote: >-
      Jio encourages responsible disclosure of security bugs by security researchers.
      All bugs or security vulnerabilities reported to us will be analysed and evaluated
      by our Application Security Experts who will then work along with you to address
      and fix them.
  - source: https://www.jio.com/security
    kind: disclosure-page
    status: 200
    note: Redirects to https://www.jio.com/page-not-found.html - no disclosure page.
  - source: https://www.jio.com/responsible-disclosure
    kind: disclosure-page
    status: 200
    note: Redirects to https://www.jio.com/page-not-found.html.