TELUS · Vulnerability Disclosure

Telus Vulnerability Disclosure

Vulnerability disclosure

TELUS publishes a security-issue reporting page and has a program registered on HackerOne, but neither is machine-readable and neither is fully verifiable anonymously: www.telus.com returns HTTP 403 to every automated client behind Cloudflare, and the HackerOne program's policy is not public. Recorded with the exact confidence the evidence supports — no security.txt, no published bug-bounty terms, no PGP key, no disclosure SLA.

TELUS runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

TelecommunicationsCanadaMobile Network OperatorBroadbandNetwork APIsCAMARAOpen GatewaySIM SwapIdentity VerificationLocation IntelligenceIoT5GHealthcareElectronic Medical RecordsGraphQLWebhooksGeospatial
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
description: >-
  TELUS publishes a security-issue reporting page and has a program registered on HackerOne, but
  neither is machine-readable and neither is fully verifiable anonymously: www.telus.com returns
  HTTP 403 to every automated client behind Cloudflare, and the HackerOne program's policy is not
  public. Recorded with the exact confidence the evidence supports — no security.txt, no published
  bug-bounty terms, no PGP key, no disclosure SLA.
policy:
- https://www.telus.com/en/about/security/report-a-problem
contact: []
contact_note: >-
  The reporting page instructs the reporter to email details of a cyber-security problem with a
  TELUS product or service; the address itself could not be read anonymously (Cloudflare 403) and is
  therefore deliberately not recorded rather than guessed.
security_txt: false
bug_bounty:
  platform: HackerOne
  handle: telus_old
  url: https://hackerone.com/telus_old
  public_policy: false
  state: unknown
  note: >-
    The HackerOne GraphQL API confirms a team with handle "telus_old" and name "TELUS_old" exists
    (https://hackerone.com/telus_old returns HTTP 200), but state, submission_state, policy and
    offers_bounties are all null to anonymous callers — the program is private or archived. There is
    no hackerone.com/telus (404), and no Bugcrowd or Intigriti program was found.
evidence:
- source: https://www.telus.com/en/about/security/report-a-problem
  kind: disclosure-page
  title: 'Report a problem regarding fraud and spam - Security | TELUS'
  http_status: 403
  status_note: Cloudflare bot challenge for automated clients; page existence and purpose confirmed via search index.
- source: https://www.telus.com/en/about/security/telus-commitment-to-security
  kind: security-policy-page
  http_status: 403
  status_note: Same Cloudflare gate.
- source: https://hackerone.com/telus_old
  kind: bug-bounty-platform
  http_status: 200
  status_note: Program exists; policy fields null to anonymous callers.
- source: https://help.inputhealth.com/.well-known/security.txt
  kind: security.txt
  http_status: 200
  status_note: >-
    Valid RFC 9116 file, but it is Intercom's (the CHR help-centre vendor) — Contact
    https://bugcrowd.com/intercom and mailto:security@intercom.com, Canonical
    https://app.intercom.com/.well-known/security.txt. Not a TELUS disclosure channel.
probes_negative:
- {url: 'https://www.telus.com/.well-known/security.txt', status: 403}
- {url: 'https://telus.com/.well-known/security.txt', status: 403}
- {url: 'https://api.telus.com/.well-known/security.txt', status: 503}
- {url: 'https://support.api.telus.com/.well-known/security.txt', status: 404}
- {url: 'https://location-api.insights.telus.com/.well-known/security.txt', status: 404}
- {url: 'https://docs.insights.telus.com/.well-known/security.txt', status: 404}
- {url: 'https://security.telus.com/', status: DNS NXDOMAIN}
confidence: medium
confidence_note: >-
  A first-party security reporting page and a HackerOne program both exist; the machine-readable
  layer (security.txt, published policy, named contact, disclosure SLA) does not.