Singtel · Vulnerability Disclosure

Singtel Vulnerability Disclosure

Vulnerability disclosure

Singtel runs a coordinated vulnerability disclosure program on Hackerone.

TelecommunicationsSingaporeMobile Network OperatorNetwork APIsCAMARAOpen GatewaySIM SwapIdentity VerificationAnti-FraudCPaaSMessagingVoiceIoT5GEdge ComputingAdunaPartner Gated
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

singtel-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: true
source: https://vdp.singtel.com/
note: >-
  Singtel runs a real, first-party vulnerability disclosure programme and links it from
  the global footer of www.singtel.com as "Vulnerability disclosure". It is operated both
  as a Singtel-hosted intake application (vdp.singtel.com, a Quasar/Vue single-page app
  titled "VDP" with the meta description "Vulnerability Disclosure Policy") and as a
  HackerOne programme (hackerone.com/singtel, titled "Singtel | Vulnerability Disclosure
  Policy"). This is a disclosure programme rather than a paid bug bounty; Singtel's own
  sustainability reporting describes it as a channel through which "customers, users and
  partners can report any potential vulnerabilities and errors in their products and
  services". Note the asymmetry worth recording: the programme exists and is prominently
  linked, but Singtel publishes no RFC 9116 /.well-known/security.txt on any host
  (see well-known/singtel-well-known.yml), so machine discovery of it fails.
policy:
- https://vdp.singtel.com/
- https://hackerone.com/singtel
contact: []
platform: HackerOne
program_type: vulnerability-disclosure
bug_bounty: false
security_txt: false
evidence:
- source: https://www.singtel.com/personal/support/broadband/maintenance-notice
  kind: site-footer-link
  detail: 'Footer link labelled "Vulnerability disclosure" → https://vdp.singtel.com/ (first-party confirmation).'
  status: 200
  fetched: '2026-07-25'
- source: https://vdp.singtel.com/
  kind: disclosure-portal
  detail: 'HTTP 200; <title>VDP</title>, meta description "Vulnerability Disclosure Policy".'
  status: 200
  fetched: '2026-07-25'
- source: https://hackerone.com/singtel
  kind: bug-bounty-platform
  detail: 'HTTP 200; HackerOne programme page titled "Singtel | Vulnerability Disclosure Policy".'
  status: 200
  fetched: '2026-07-25'
- source: https://www.singtel.com/personal/support/broadband/security-feedback
  kind: security-feedback-page
  detail: Consumer-facing broadband security feedback page (HTTP 200) — a separate, lower-tier reporting channel.
  status: 200
  fetched: '2026-07-25'