TELUS · Vulnerability Disclosure

Telus Vulnerability Disclosure

Vulnerability disclosure

TELUS publishes a security-issue reporting page and has a program registered on HackerOne, but neither is machine-readable and neither is fully verifiable anonymously: www.telus.com returns HTTP 403 to every automated client behind Cloudflare, and the HackerOne program's policy is not public. Recorded with the exact confidence the evidence supports — no security.txt, no published bug-bounty terms, no PGP key, no disclosure SLA.

TELUS runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

TelecommunicationsCanadaMobile Network OperatorBroadbandNetwork APIsCAMARAOpen GatewaySIM SwapIdentity VerificationLocation IntelligenceIoT5GHealthcareElectronic Medical RecordsGraphQLWebhookGeospatial
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
description: >-
  TELUS publishes a security-issue reporting page and has a program registered on HackerOne, but
  neither is machine-readable and neither is fully verifiable anonymously: www.telus.com returns
  HTTP 403 to every automated client behind Cloudflare, and the HackerOne program's policy is not
  public. Recorded with the exact confidence the evidence supports — no security.txt, no published
  bug-bounty terms, no PGP key, no disclosure SLA.
policy:
- https://www.telus.com/en/about/security/report-a-problem
contact: []
contact_note: >-
  The reporting page instructs the reporter to email details of a cyber-security problem with a
  TELUS product or service; the address itself could not be read anonymously (Cloudflare 403) and is
  therefore deliberately not recorded rather than guessed.
security_txt: false
bug_bounty:
  platform: HackerOne
  handle: telus_old
  url: https://hackerone.com/telus_old
  public_policy: false
  state: unknown
  note: >-
    The HackerOne GraphQL API confirms a team with handle "telus_old" and name "TELUS_old" exists
    (https://hackerone.com/telus_old returns HTTP 200), but state, submission_state, policy and
    offers_bounties are all null to anonymous callers — the program is private or archived. There is
    no hackerone.com/telus (404), and no Bugcrowd or Intigriti program was found.
evidence:
- source: https://www.telus.com/en/about/security/report-a-problem
  kind: disclosure-page
  title: 'Report a problem regarding fraud and spam - Security | TELUS'
  http_status: 403
  status_note: Cloudflare bot challenge for automated clients; page existence and purpose confirmed via search index.
- source: https://www.telus.com/en/about/security/telus-commitment-to-security
  kind: security-policy-page
  http_status: 403
  status_note: Same Cloudflare gate.
- source: https://hackerone.com/telus_old
  kind: bug-bounty-platform
  http_status: 200
  status_note: Program exists; policy fields null to anonymous callers.
- source: https://help.inputhealth.com/.well-known/security.txt
  kind: security.txt
  http_status: 200
  status_note: >-
    Valid RFC 9116 file, but it is Intercom's (the CHR help-centre vendor) — Contact
    https://bugcrowd.com/intercom and mailto:security@intercom.com, Canonical
    https://app.intercom.com/.well-known/security.txt. Not a TELUS disclosure channel.
probes_negative:
- {url: 'https://www.telus.com/.well-known/security.txt', status: 403}
- {url: 'https://telus.com/.well-known/security.txt', status: 403}
- {url: 'https://api.telus.com/.well-known/security.txt', status: 503}
- {url: 'https://support.api.telus.com/.well-known/security.txt', status: 404}
- {url: 'https://location-api.insights.telus.com/.well-known/security.txt', status: 404}
- {url: 'https://docs.insights.telus.com/.well-known/security.txt', status: 404}
- {url: 'https://security.telus.com/', status: DNS NXDOMAIN}
confidence: medium
confidence_note: >-
  A first-party security reporting page and a HackerOne program both exist; the machine-readable
  layer (security.txt, published policy, named contact, disclosure SLA) does not.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/telus-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.