🇺🇸 United States · snapshot 2026-06-21 · 100 companies · graded against the disclose.io Maturity Model
| # | Company | Report | Policy | Disclose.io Maturity Level | Last verified | |
|---|---|---|---|---|---|---|
| 1 | Amazon amazon.com |
Web form ↗ | policy ↗ | L1 | 2026-06-21 | ▸ |
Contact Only policy text · confidence high
Report via: https://hackerone.com/amazonvrp · Policy: https://aws.amazon.com/.well-known/security.txt
“Contact: mailto:aws-security@amazon.com | AWS Vulnerability Disclosure Program: https://hackerone.com/aws_vdp | Policy: https://vdp.aws.security/” | ||||||
| 2 | Walmart walmart.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://corporate.walmart.com/article/responsible-disclosure-policy · Policy: https://corporate.walmart.com/article/responsible-disclosure-policy
“Walmart Responsible Disclosure Policy: 'We will not take legal action against, or suspend or terminate the accounts of, researchers who discover and report security vulnerabilities in accordance with this Responsible Disclosure Policy.' Promissory non-pursuit, but testing NOT explicitly authorized, no CFAA/DMCA/ToS carve-out, no timeline → L3. security.txt live, Contact → policy.” | ||||||
| 3 | UnitedHealth Group unitedhealthgroup.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence high
Report via: Securityreporting@optum.com · Policy: https://www.optum.com/vulnerability.html
“This policy prohibits the performance of the following activities: Hacking, penetration testing, or other attempts to gain unauthorized access to UnitedHealth Group software or systems; Active vulnerability scanning or testing; | If you have discovered an issue that you believe is an in-scope vulnerability, please email securityreporting@optum.com | The following types of vulnerabilities are considered out of the scope for the purposes of this program: Volumetric vulnerabilities (e.g., Denial of Service or Distributed DoS); Reports of non-exploitable vulnerabilities... | The time to address a valid, reported vulnerability will vary based on impact of the potential vulnerability and affected systems. | For the security of our customers, UnitedHealth Group will not disclose, discuss, or confirm security issues. | Security researchers must not violate any law, or access, use, alter or compromise in any manner any UnitedHealth Group data.” | ||||||
| 4 | Apple apple.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence high
Report via: https://security.apple.com/bounty/guidelines/ · Policy: https://security.apple.com/bounty/guidelines/
“For Product categories, the issue must affect the latest publicly available version (including beta versions) of iOS, iPadOS, macOS, tvOS, visionOS, or watchOS, with a standard configuration and on publicly available Apple hardware or Security Research Device. | For Services, the issue must relate to a web server or service owned by Apple or an Apple subsidiary. | Submit your report online to help ensure that you receive timely updates, can add additional information as needed, and can communicate with Apple security engineers about your report. | We make it a priority to resolve security and privacy issues as quickly as possible, and most reports are resolved within 90 days. | Publicly disclosing security issues before a fix is available makes you ineligible for all Apple Security Bounty rewards.” | ||||||
| 5 | Alphabet google.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP web search · confidence medium
Report via: https://g.co/vulnz · Policy: https://bughunters.google.com/about/rules/google-friends/google-and-alphabet-vulnerability-reward-program-vrp-rules
“Google & Alphabet VRP (Bug Hunters), live since 2010. Scope: 'any Google-owned or Alphabet (Bet) subsidiary web service that handles reasonably sensitive user data'. Authorization language is RESTRICTIVE only: 'The Vulnerability Reward Program does not authorize the testing of Google Cloud customer applications...'. No affirmative safe-harbor, no 'will not pursue legal action', no CFAA/DMCA/ToS carve-out, no CVD deadline in the VRP policy. security.txt: Contact https://g.co/vulnz + security@google.com; Policy https://g.co/vrp.” | ||||||
| 6 | CVS Health cvshealth.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence high
Report via: https://www.cvshealth.com/vulnerability-disclosure-program · Policy: https://www.cvshealth.com/vulnerability-disclosure-program
“we encourage you to report it by using this page. Your report will be forwarded for timely acknowledgement and verification. Verified issues will then be passed to our development teams for remediation on a timeline commensurate with the severity of the issue. | Any exfiltration or downloading of CVS Health/Aetna data, disclosure of confidential information, and/or disrupting our customers' experience are all outside the scope of this program and outside any protections it affords from legal recourse. | You are expected to engage in security research responsibly. | Per our policy, if you wish to take part in the CVS Health Vulnerability Disclosure Program, you are expected to follow these guidelines” | ||||||
| 7 | Berkshire Hathaway berkshirehathaway.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No public channel. hackerone.com/berkshirehathaway is a legacy directory stub (GraphQL submission_state=null, policy=null, scopes=[]). security.txt 404 at all paths (genuine Apache 404, not WAF). Search hits claiming a VDP are AI inferences from the empty stub. Prior 'none' confirmed.” | ||||||
| 8 | McKesson mckesson.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence high
Report via: mailto:mckesson@submit.bugcrowd.com · Policy: https://www.mckesson.com/cybersecurity/coordinated-vulnerability-disclosure/
“please submit it in the form below or email VulnerabilityReporting@McKesson.com | We will contact you to confirm that we've received your report and trace your steps to reproduce your research. We will work with the affected teams to validate the report. We will notify you of remediation | Do not hack, penetrate, or attempt to gain access to McKesson infrastructure, systems, or data | you agree to comply with McKesson's Terms of Service, McKesson's Privacy Policy, and all applicable state, federal, or international laws and regulations | you may not publicly disclose your findings or the contents of your Submission to any third parties. McKesson's program does not permit disclosure to any party outside of McKesson” | ||||||
| 9 | Exxon Mobil exxonmobil.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No public channel. hackerone.com/exxonmobil is an unclaimed community stub — real-Chrome render reads 'There are no known guidelines for reporting potential security vulnerabilities to this organization.' + 'This page is not affiliated with ExxonMobil.' GraphQL: empty policy/email, offers_rewards=false. security.txt 404. Prior 'none' confirmed.” | ||||||
| 10 | Cencora cencora.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No org-operated channel. Only artifact is an unclaimed HackerOne community stub at hackerone.com/healthcareabc (AmerisourceBergen) — real-Chrome render: 'There are no known guidelines...' + 'This page is not affiliated...' + 'Claim this page'. No scope/submit/policy/email. Below L1. Prior 'none' confirmed.” | ||||||
| 11 | Microsoft microsoft.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence high
Report via: https://www.microsoft.com/en-us/msrc/bounty-safe-harbor · Policy: https://www.microsoft.com/en-us/msrc/bounty-safe-harbor
“Microsoft Bounty Program is subject to these terms and those outlined in the Microsoft Bounty Terms and Conditions , Microsoft Bounty Legal Safe Harbor , Rules of Engagement , Bounty Program Guidelines | Cloud Programs Up to $100,000 USD ... Endpoint & On-Prem Programs Up to $250,000 USD ... Zero Day Quest Up to $100,000 USD | Report vulnerabilities privately and allow time for remediation before public disclosure. Adhere to our Rules of Engagement and program scope to ensure eligibility for awards. | Do not access, modify, or exfiltrate customer data. Never disrupt services or compromise uptime.” | ||||||
| 12 | JPMorgan Chase jpmorganchase.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence high
Report via: https://responsibledisclosure.jpmorganchase.com · Policy: https://responsibledisclosure.jpmorganchase.com
“Typical Vulnerabilities Accepted: OWASP Top 10 vulnerability categories Other vulnerabilities with demonstrated impact | Typical Out of Scope: Theoretical vulnerabilities Informational disclosure of non-sensitive data Low impact session management issues Self XSS (user defined payload) | Work directly with the JPMorgan Chase Responsible Disclosure Program on vulnerability submissions | you will be allowed to disclose the vulnerability after a fix has been issued | Adhere to all legal terms and conditions outlined at ResponsibleDisclosure.JPMorganChase.com” | ||||||
| 13 | Costco Wholesale costco.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/costco · Policy: https://hackerone.com/costco
“LIVE HackerOne VDP (GraphQL submission_state=open, public_mode, offers_bounties=false). Safe Harbor: 'We do not intend to assert claims under computer abuse laws for activities conducted in a manner consistent with this policy... if legal action is initiated by a third party... we will take steps to make it known that your actions were conducted in compliance with this policy.' Promissory + CFAA reference, but testing NOT explicitly authorized, no DMCA/ToS carve-out → L3. security.txt at www.costco.com/security.txt (root). Prior L1 undercounted → L3.” | ||||||
| 14 | Cigna Group cigna.com |
Email ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: security@cigna.com · Policy: https://www.cigna.com/legal/members/responsible-vulnerability-disclosure
“VDP at cigna.com/legal/members/responsible-vulnerability-disclosure. Safe harbor: 'We will not pursue legal action against you if you act in good faith... comply with these Guidelines...'. CVD timeline: 'Please provide us a minimum of 90 days... After this 90 day period, you may publicly disclose...'. Submit via security@cigna.com (PGP). No explicit testing authorization, no CFAA/DMCA/ToS carve-out → L3 (has a 90-day clock but testing not authorized). Prior L1 undercounted → L3.” | ||||||
| 15 | Cardinal Health cardinalhealth.com |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP web search · confidence high
Report via: GMB-MedicalDeviceSecurity@cardinalhealth.com · Policy: https://www.cardinalhealth.com/en/support/coordinated-vulnerability-disclosure.html
“Coordinated Vulnerability Disclosure process: report via email to GMB-MedicalDeviceSecurity@cardinalhealth.com; scope = supported/connected medical devices. No safe-harbor or testing authorization. (hackerone.com/cardinal_health is a non-operational directory placeholder.)” | ||||||
| 16 | Nvidia nvidia.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence medium
Report via: https://www.intigriti.com/programs/nvidia/nvidiavdp/detail · Policy: https://www.intigriti.com/programs/nvidia/nvidiavdp/detail
“This is a responsible disclosure program without bounties. | Your Submission must be for an Asset (herein referred to as "product" and/or "technology") that is identified as in scope of the NVIDIA Program(s). | You are required to report a discovered Vulnerability in a prompt and transparent manner through the Platform. | You agree to conduct your research within the bounds of Ethical Hacking. | You agree to practice coordinated disclosure in all of your security research conducted under the Program” | ||||||
| 17 | Meta Platforms meta.com |
Web form ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: https://www.facebook.com/whitehat/report/ · Policy: https://bugbounty.meta.com/terms/
“First-party Meta Bug Bounty (not HackerOne). Testing auth + CFAA: 'We consider these terms to provide you authorization, including under the Computer Fraud and Abuse Act (CFAA)... to test the security of the products and systems identified as in-scope.' Safe harbor: 'we will not initiate a complaint to law enforcement or pursue a civil action against you.' DMCA: 'Meta will also not pursue... DMCA claims against you for circumventing the technological measures...'. ToS waiver: 'To the extent activities authorized by these Meta Bug Bounty terms are inconsistent with other terms of service... we waive those restrictions.' No day-count deadline → L4. Prior directory-L2 was a major miss.” | ||||||
| 18 | Elevance Health elevancehealth.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. Only HackerOne presence (antheminc, former name) is a community stub ('There are no known guidelines...', 'not affiliated with Anthem'). security.txt 404 (elevancehealth.com + anthem.com). Own cybersecurity page is internal governance only. Prior 'none' confirmed.” | ||||||
| 19 | Centene centene.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/centene_vdp · Policy: https://hackerone.com/centene_vdp?type=team
“Active HackerOne VDP at hackerone.com/centene_vdp (HTTP 200, type VDP). 'Any activities conducted in a manner consistent with this policy will be considered authorized conduct, and we will not initiate legal action against you' + third-party defense = safe harbor + authorization (L3). policy_versions grep: zero CFAA/DMCA/ToS/timeline → no L4/L5. Prior 'none' matched the empty /centene stub, not the real _vdp program.” | ||||||
| 20 | Bank of America bankofamerica.com |
PSIRT ↗ | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
Report via: https://www.first.org/members/teams/bank_of_america_cyber_threat_defence
“hackerone.com/bofa is an empty stub (GraphQL submission_state=null, validated against working controls). bankofamerica handle NOT_FOUND. Bugcrowd 404 (3 slugs). Synack ECONNREFUSED. security.txt 404. security-center is consumer fraud/phishing only, no researcher channel. Prior L1 was a false channel → L0.” | ||||||
| 21 | Chevron chevron.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“hackerone.com/chevron is an unclaimed community stub (real-Chrome: 'There are no known guidelines...', 'not affiliated with Chevron', no submit). Bugcrowd 404. Synack ECONNREFUSED. No security.txt (404 www+apex). Own cybersecurity page is internal-only. Prior 'none' confirmed.” | ||||||
| 22 | Ford Motor ford.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/ford · Policy: https://hackerone.com/ford?view_policy=true
“Live HackerOne VDP ('Ford - Vulnerability Disclosure Program'; also a Bugcrowd coordinated-disclosure engagement). Safe harbor (via FireBounty mirror + WebFetch): 'Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you' + third-party support. Scope *.ford.com/*.lincoln.com + FordPass + vehicle hardware. No CFAA/DMCA/ToS, no deadline → L3. Prior 'none'/timeout was wrong.” | ||||||
| 23 | General Motors gm.com |
HackerOne ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor web search · confidence high
Report via: https://hackerone.com/gm/reports/new?type=team&report_type=vulnerability · Policy: https://hackerone.com/gm
“Live public HackerOne VDP (submission_state=open, public_mode). 'GM agrees not to pursue civil action against researchers who comply...'; activities consistent with the policy are '"authorized" conduct under the Computer Fraud and Abuse Act'; '...we will not bring a DMCA claim...'. No explicit ToS carve-out and no published CVD deadline (disclosure gated on remediation).” Source: https://hackerone.com/gm | ||||||
| 24 | Citigroup citi.com |
Bugcrowd ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: https://bugcrowd.com/engagements/citi · Policy: https://bugcrowd.com/engagements/citi
“Live Bugcrowd VDP (state in_progress, open, scope 'Any Citigroup owned asset', no_reward). Citi's authored policy DISCLAIMS authorization/safe harbor: 'this program should not be construed as encouragement or permission to perform... Hack, penetrate or otherwise attempt to gain unauthorized access... Citi does not waive any rights or claims.' → real VDP but no safe harbor = L2 (authored prose governs over Bugcrowd's generic badge).” | ||||||
| 25 | Home Depot homedepot.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No current channel. security.txt 404 (live only in a single 2023 snapshot, gone since). Synack host homedepot.responsibledisclosure.com now NXDOMAIN (VDP decommissioned). No HackerOne/Bugcrowd. TechCrunch (2025-12-12): 'Home Depot does not have a way to report security flaws, such as a vulnerability disclosure or bug bounty program.' Prior 'none' confirmed.” | ||||||
| 26 | Fannie Mae fanniemae.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP web search · confidence high
Report via: https://www.fanniemae.com/form/report-technology-vulnerability · Policy: https://www.fanniemae.com/about-us/reporting-technology-vulnerability
“Working vulnerability-report web form on own domain (fields for location/URL, repro steps, impact, PoC, reporter email). No safe-harbor/no-legal-action promise, no testing authorization; reports may be shared with law enforcement. (hackerone.com/fanniemae is a directory placeholder.)” | ||||||
| 27 | Kroger kroger.com |
Bugcrowd ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/kroger-vdp · Policy: https://bugcrowd.com/engagements/kroger-vdp
“Live Bugcrowd VDP (no_reward, open). Explicit authorization: 'Testing is authorized on the websites and applications in scope.' Safe harbor: 'We consider any security research conducted in good faith and in compliance with this Policy to be authorized conduct and we will not initiate legal action against you... If legal action is initiated by a third party... we will take steps to make it known that your actions were authorized.' No CFAA/DMCA/ToS carve-out; disclosure gated on consent (no timeline) → L3. security.txt routes Contact to bugcrowd.com/kroger-vdp. Prior L1 undercounted → L3.” | ||||||
| 28 | Verizon verizon.com |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP web search · confidence high
Report via: vecirt-incident@verizon.com · Policy: https://www.verizon.com/solutions-and-services/report-security-vulnerability/
“Official 'Report Security Vulnerability' page; submit via vecirt-incident@verizon.com (routed to CIRT). Explicitly anti-safe-harbor: 'Verizon does not endorse, solicit, or request independent testing... for security vulnerabilities' and requires following all Terms and Conditions. No carve-out, no timeline.” | ||||||
| 29 | Phillips 66 phillips66.com |
HackerOne ↗ | policy ↗ | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence low
Report via: https://hackerone.com/phillips66co · Policy: https://hackerone.com/phillips66co
“CONFIRMED LIVE HackerOne VDP: GraphQL team(handle:'phillips66co') resolves to a real registered program 'Phillips 66' (energy co, distinct from healthcare 'philips'). No-bounty VDP. BUT policy markdown is UNREADABLE via every unauthenticated channel (live + Wayback are JS shells; GraphQL policy:null), so exact level could not be read — ≥L2 floor, L3/L4/L5 indeterminate. Level NOT guessed (unverified). security.txt 404. Bugcrowd 404.” | ||||||
| 30 | Marathon Petroleum marathonpetroleum.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel for MPC. No owned VDP/PSIRT/security page — corporate ToU is anti-testing: prohibits 'attempting to probe, scan, or test the vulnerability of any system' and 'will cooperate with law enforcement'. HackerOne /marathonpetroleum = Page not found. Bugcrowd 404. Synack no DNS. security.txt absent (Wayback 404 both 2023 snapshots). Prior 'none' confirmed (hostile posture).” | ||||||
| 31 | StoneX Group stonex.com |
security.txt ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: itsecurity@stonex.com
“Live security.txt (200): 'Contact: mailto:itsecurity@stonex.com / Encryption: .../itsecurity.pgp / Hiring: ...'. NO Policy: field, no scope, no submission form, no safe-harbor. Contact-only. No owned VDP, no HackerOne/Bugcrowd, no Synack. Prior L1 confirmed.” | ||||||
| 32 | State Farm statefarm.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor policy text · confidence high
Report via: https://bugcrowd.com/vulnerability-rating-taxonomy · Policy: https://www.statefarm.com/customer-care/privacy-security/security/vulnerability-disclosure-policy
“State Farm will not take legal action against you or revoke access to State Farm applications | If you have noticed an information security issue in a State Farm system while using www.statefarm.com or a State Farm mobile application, we want to hear about it | Please disclose issues using the Vulnerability Disclosure Communication form located on this web page | State Farm will work to address the issue in a timely fashion | We reserve all legal rights in the event of noncompliance” | ||||||
| 33 | Freddie Mac freddiemac.com |
Bugcrowd ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP web search · confidence high
Report via: https://bugcrowd.com/engagements/freddie-mac-vdp-ess · Policy: https://www.freddiemac.com/terms/vulnerability_disclosure_policy
“VDP on own domain: 'applies to all internet-facing assets...'. Triaged by Bugcrowd; no bounty. No safe-harbor/no-legal-action promise, no testing authorization, no carve-out, no timeline.” | ||||||
| 34 | Humana humana.com |
security.txt ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only web search · confidence high
Report via: bugbounty@humana.com
“security.txt resolves at ROOT (humana.com/security.txt; /.well-known/ 404s), HTTP 200: 'Contact: mailto:bugbounty@humana.com / Expires: 2026-01-01 / Hiring: ...'. No Policy: field, no public HackerOne/Bugcrowd program. Contact-only. (Expires date is in the past.)” | ||||||
| 35 | AT&T att.com |
HackerOne ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: https://hackerone.com/att · Policy: https://hackerone.com/att?view_policy=true
“Real open HackerOne program (GraphQL submission_state=open, public_mode, bounties $50-$3,000). Scope + submit path = L2. NO safe harbor/authorization/carve-out. Restrictive: 'You may only exploit... your own accounts. Testing must not violate any law...' + injunctive-relief threat. No security.txt. Prior L1 undercounted.” | ||||||
| 36 | Goldman Sachs goldmansachs.com |
HackerOne ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: https://hackerone.com/goldmansachs · Policy: https://hackerone.com/goldmansachs?view_policy=true
“Real open HackerOne program (GraphQL submission_state=open, public_mode, bounties). Scope (*.gs.com, *.goldmansachs.com) + Submit = L2. No promissory safe harbor (only HackerOne boilerplate). No carve-out, no timeline ('will not be publicly disclosing reports at this time'). Prior L1 undercounted.” | ||||||
| 37 | Comcast xfinity.com |
Bugcrowd ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: securitydefectreporting@comcast.com · Policy: https://bugcrowd.com/engagements/comcastvdp
“Real public Bugcrowd program 'Comcast Xfinity VDP' (slug comcastvdp, participation=open, 1,459 rewarded). Brief safeHarborStatus='full' (= CFAA/CMA + DMCA + ToS/AUP carve-outs per Bugcrowd/disclose.io definition). 'Testing is only authorized on the targets listed as in scope.' No published disclosure deadline → L4. xfinity.com/vulnerabilityreport routes here. (hackerone.com/comcast is a null stub.) Prior L1 was a major miss.” | ||||||
| 38 | Wells Fargo wellsfargo.com |
Email ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: ResponsibleDisclosure@wellsfargo.com · Policy: https://www.wellsfargo.com/privacy-security/fraud/responsible-disclosure-program/
“First-party policy: 'Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you.' + third-party defense language. Testing authorized + non-pursuit = L3. No CFAA/DMCA/ToS carve-out, no disclosure timeline. Email submission; public disclosure prohibited without permission. Prior L1 undercounted.” | ||||||
| 39 | Morgan Stanley morganstanley.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence high
Report via: https://morganstanley.responsibledisclosure.com/ · Policy: https://morganstanley.responsibledisclosure.com/
“Typical Vulnerabilities Accepted: OWASP Top 10 vulnerability categories Other vulnerabilities with demonstrated impact | Typical Out of Scope: Theoretical vulnerabilities Informational disclosure of non-sensitive data Low impact session management issues Self XSS (user defined payload) | To work directly with ResponsibleDisclosure.com on vulnerability submissions in good faith | you will be allowed to disclose the vulnerability after a fix has been issued | Not to engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of information and systems” | ||||||
| 40 | Valero Energy valero.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 both paths (HTML). HackerOne valero = team does not exist; valeroenergy = null community stub. Bugcrowd 404. Synack no DNS. Legal Notice PROHIBITS testing ('Probes, scans, or tests the vulnerability... without proper authorization'); only generic privacy emails. Prior 'none' confirmed.” | ||||||
| 41 | Dell Technologies dell.com |
Web form ↗ | policy ↗ | L1 | 2026-06-21 | ▸ |
Contact Only policy text · confidence high
Report via: https://bugcrowd.com/dell-com · Policy: https://afcs.dell.com/.well-known/security.txt
“Contact: https://www.dell.com/support/dell-vulnerability-response-policy # Bug Bounty Program - Applications | Contact: https://bugcrowd.com/dell-com # Bug Bounty Program - Products | Contact: https://bugcrowd.com/dell-product | Policy: https://www.dell.com/support/dell-vulnerability-response-policy” | ||||||
| 42 | Target target.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor web search · confidence high
Report via: security@target.com · Policy: https://security.target.com/vdp/
“Policy on own domain (security.target.com/vdp/). Scope: 'any of Target's guest-facing online services.' Safe harbor: 'Target will not take legal action against you related to any activities conducted in a manner consistent with this Policy and otherwise in good faith.' Submissions via HackerOne. No explicit authorization to test or statutory carve-outs.” | ||||||
| 43 | Tesla tesla.com |
Bugcrowd ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor web search · confidence high
Report via: VulnerabilityReporting@tesla.com · Policy: https://www.tesla.com/legal/security
“security.txt at /.well-known/ (confirmed via Wayback; live edge WAF-blocks non-browsers). Policy tesla.com/legal/security: 'pre-approved, good-faith security researcher... has not accessed a computer without authorization... under the CFAA' (CFAA) and 'will not bring a copyright infringement claim under the DMCA... who circumvents security mechanism' (DMCA). Authorization gated on pre-registration; no explicit ToS waiver; disclosure 'reasonable time' (no fixed deadline) → L3. Public Bugcrowd program bugcrowd.com/tesla.” | ||||||
| 44 | Walt Disney disney.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/disney · Policy: https://hackerone.com/disney
“Real open HackerOne program (GraphQL submission_state=open, public_mode, 'The Walt Disney Company'). Conditional non-pursuit: 'If we conclude, in our sole discretion, that you have complied... TWDC will not pursue claims against you in response to your report.' Testing NOT broadly authorized; no carve-outs; SLAs are response targets not a CVD deadline. Scope incl. Disney+, ESPN, Marvel, etc. Prior L1 undercounted → L3.” | ||||||
| 45 | Johnson & Johnson jnj.com |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP web search · confidence high
Report via: vulnerability_reporting@its.jnj.com · Policy: https://www.jnj.com/coordinated-vulnerability-disclosure-statement
“Vulnerability Reporting Program scope = 'J&J's infrastructure, websites, public APIs, and applications'; report via vulnerability_reporting@its.jnj.com (devices via productsecurity@jnj.com). 10-business-day acknowledgment; asks to 'Comply with all laws.' No safe-harbor language. Also runs hackerone.com/jnj.” | ||||||
| 46 | PepsiCo pepsico.com |
HackerOne ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: https://hackerone.com/pepsico_vdp · Policy: https://hackerone.com/pepsico_vdp
“HackerOne 'pepsico_vdp' (GraphQL submission_state=open, public_mode). Real VDP with scope/rules but NO safe-harbor/legal/authorization language → L2. Bare 'pepsico' = team does not exist; no security.txt (404); no Synack/Bugcrowd. Prior L1 undercounted.” | ||||||
| 47 | Boeing boeing.com |
Web form ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor policy text · confidence high
Report via: https://www.boeing.com/vulnerabilitydisclosure · Policy: https://www.boeing.com/vulnerabilitydisclosure
“Boeing will not pursue civil action or initiate a complaint to law enforcement for accidental, good faith violations of this policy. | We consider activities conducted consistent with this policy to constitute authorized access under anti-hacking laws. | To the extent your activities are inconsistent with certain Boeing terms and conditions, we waive those restrictions for the limited purpose of permitting security research under this policy. | Provide Boeing reasonable time to fix any reported issue, before such information is shared with a third party or disclosed publicly.” | ||||||
| 48 | UPS ups.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/ups · Policy: https://hackerone.com/ups
“HackerOne 'ups' (UPS VDP, GraphQL open/public_mode). Safe Harbor: 'Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party... we will take steps to make it known that your actions were conducted in compliance with this policy.' Authorization + non-pursuit but no CFAA/DMCA/ToS carve-out, no deadline → L3. No security.txt (404). Prior L1 undercounted.” | ||||||
| 49 | RTX rtx.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP web search · confidence high
Report via: https://www.rtx.com/contacts/vulnerability-reporting · Policy: https://www.rtx.com/contacts/vulnerability-reporting
“VDP on own domain with embedded web form. Scope: 'public facing RTX product, system, or asset'. Asks to 'Provide RTX reasonable time to resolve.' No safe-harbor, no authorization, no timeline. Also listed on hackerone.com/rtx.” | ||||||
| 50 | FedEx fedex.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor web search · confidence high
Report via: https://fedex.responsibledisclosure.com/hc/en-us/requests/new · Policy: https://www.synack.com/vdp/fedex/
“VDP managed by Synack. Scope *.fedex.com. Safe harbor: 'Synack will not bring a private action against you or refer the matter for public inquiry.' Submit via fedex.responsibledisclosure.com. (Trust Center landing page intermittently 503s.)” | ||||||
| 51 | Progressive progressive.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“Only an empty HackerOne community stub (hackerone.com/progressivecorp — GraphQL state=null, policy=null, external_program). Own /security/ 404; security.txt both paths = branded 404. No real HackerOne program (4 slugs none); no Bugcrowd (404); no Synack (NXDOMAIN). Prior 'none' confirmed.” | ||||||
| 52 | Lowe's lowes.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/lowes · Policy: https://hackerone.com/lowes
“HackerOne 'lowes' (Lowe's Companies VDP, GraphQL open/public_mode). Non-pursuit: "Lowe's will not take legal action against or suspend or terminate the accounts of those who discover and report security vulnerabilities in accordance with this Vulnerability Disclosure Policy." Full scope + SLAs (real VDP). No explicit testing authorization, no CFAA/DMCA/ToS carve-out, no deadline → L3. (lowes.com security.txt bleeds through to an unrelated TIAA-CREF stub — not Lowe's.) Prior L1 undercounted.” | ||||||
| 53 | Energy Transfer energytransfer.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne 'Team does not exist' (4 slugs). No Bugcrowd (404). No Synack (NXDOMAIN). security.txt behind F5 WAF 403 with no real file. Only a corporate privacy mailbox (not a researcher channel). Prior 'none' confirmed.” | ||||||
| 54 | Procter & Gamble pg.com |
Web form ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor policy text · confidence high
Report via: https://vdp.pg.com · Policy: https://vdp.pg.com
“we consider this research conducted under this policy to be: Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy | Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls | Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis | Public disclosure may be allowed upon request, and only after granted written permission to do so from P&G” Source: https://vdp.pg.com | ||||||
| 55 | Sysco sysco.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“Only an empty HackerOne community stub (hackerone.com/sysco — GraphQL state=null, policy=null, external_program). security.txt path returns 200 but is SPA HTML (not a real file). No real HackerOne (syscocorp none); no Bugcrowd (404); no Synack (NXDOMAIN). Prior 'none' confirmed.” | ||||||
| 56 | American Express americanexpress.com |
security.txt ↗ | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
Report via: security@swisscard.ch
“hackerone.com/americanexpress is an empty community-curated stub (GraphQL submission_state=null, policy='', external_program, scopes=[]). security.txt both paths 302→404 (Akamai). Amex security-center is consumer fraud guidance; sole email spoof@americanexpress.com is phishing, not vuln disclosure. Bugcrowd 404; Synack ECONNREFUSED. Prior L1 was a false channel → L0.” | ||||||
| 57 | Albertsons albertsons.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor web search · confidence high
Report via: https://albertsons.responsibledisclosure.com/hc/en-us · Policy: https://albertsons.responsibledisclosure.com/hc/en-us
“Responsible Disclosure powered by Synack. Submit via form. Safe harbor: '...Synack will not bring a private action against the reporter or refer the matter for public inquiry.' Disclosure only after fix. (Site 403s bots.)” | ||||||
| 58 | Archer Daniels Midland adm.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. Footer exposes only Privacy/Terms/Compliance, no security link. HackerOne /adm + /archer_daniels_midland 404 (no program/stub). Bugcrowd /engagements/adm 404. Synack ECONNREFUSED. security.txt both paths clean 404 (not WAF). Prior 'none' confirmed.” | ||||||
| 59 | MetLife metlife.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“hackerone.com/metlife is an empty community stub — real-Chrome render verbatim: 'There are no known guidelines for reporting potential security vulnerabilities to this organization.' + 'not affiliated with MetLife... Claim this page', no Submit button (submission_state null). Bugcrowd 404. Synack ECONNREFUSED. security.txt 404/403. Own pages: only phish@metlife.com (phishing). Prior 'none' confirmed.” | ||||||
| 60 | HCA Healthcare hcahealthcare.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence medium
Report via: https://www.hcahealthcare.com/legal/responsible-disclosure · Policy: https://www.hcahealthcare.com/legal/responsible-disclosure
“please let us know by emailing our Information Protection & Security team directly at Information.Protection@hcahealthcare.com | We ask that you work with us to diagnose and correct a vulnerability prior to publically disclosing it to ensure the safety and wellbeing of our patients and systems | We ask that you not perform vulnerability or similar testing on products that are actively in use for public safety reasons | In the event you share information with us, you agree that the information you submit will be considered non-proprietary and non-confidential, and that we may use such information in any manner, without restriction. Furthermore, you agree that submitting information does not create any rights for you or any obligation for us.” | ||||||
| 61 | Lockheed Martin lockheedmartin.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://www.lockheedmartin.com/en-us/contact/vulnerability-disclosure-policy.html · Policy: https://www.lockheedmartin.com/en-us/contact/vulnerability-disclosure-policy.html
“Own VDP page. Testing authorized + CFAA: 'Lockheed Martin considers security research and vulnerability disclosure activities conducted consistent with this policy to be "authorized" conduct under the Computer Fraud and Abuse Act and other applicable computer use laws.' Non-pursuit: 'will not pursue civil or criminal action... for accidental or good faith violations of this policy'. CVD timeline: 'Keep information about any vulnerabilities... confidential between yourself and Lockheed Martin until we have had minimum 120 days to verify and resolve the issue.' L4 signals + published 120-day timeline → L5. Prior L1 was a major miss (HackerOne entry was only a community stub).” | ||||||
| 62 | New York Life newyorklife.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No external channel. security.txt 404 live + Wayback (Jun 2023–Nov 2024). HackerOne 4 slugs 404; /nyl is a generic non-NYL handle. Bugcrowd 4 variants 404. Synack ECONNREFUSED. Own Information Security page describes internal defensive program only, no report mechanism. Prior 'none' confirmed.” | ||||||
| 63 | Capital One capitalone.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor policy text · confidence high
Report via: https://hackerone.com/capital-one-bounty · Policy: https://www.capitalone.com/digital/responsible-disclosure/
“By responsibly submitting your findings to Capital One in accordance with these guidelines Capital One agrees not to pursue legal action against you. | Capital One reserves all legal rights in the event of noncompliance with these guidelines. | Do not engage in any activity that violates (a) federal or state laws or regulations or (b) the laws or regulations of any country where (i) data, assets or systems reside, (ii) data traffic is routed or (iii) the researcher is conducting research activity. | Provide Capital One reasonable time to fix any reported issue. | Out of Scope Vulnerabilities Certain vulnerabilities are considered out of scope for our Responsible Disclosure Program.” | ||||||
| 64 | Allstate allstate.com |
Email ↗ | policy ↗ | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: SecurityDisclosure@infoarmor.com · Policy: https://www.allstateidentityprotection.com/security
“Allstate Identity Protection (Allstate-owned, formerly InfoArmor) security page: 'Report any potential security bug or vulnerability to SecurityDisclosure@infoarmor.com'. No scope, no testing authorization, no safe harbor, no timeline → contact-only L1. Main allstate.com has no PSIRT; security.txt times out; HackerOne empty stub; Bugcrowd 404; Synack ECONNREFUSED. Prior L1 confirmed (subsidiary channel).” | ||||||
| 65 | Caterpillar caterpillar.com |
HackerOne ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor web search · confidence high
Report via: https://hackerone.com/caterpillar · Policy: https://hackerone.com/caterpillar
“HackerOne hackerone.com/caterpillar (submission_state=open). disclose.io GOLD-STANDARD safe harbor verbatim: 'We consider Good Faith Security Research to be authorized activity that is protected from adversarial legal action by us. We waive any relevant restriction in our Terms of Service (TOS) and/or Acceptable Use Policies (AUP)... Will not bring legal action against you... including for bypassing technological measures we use to protect the applications in scope' (= testing authorized + CFAA + ToS/AUP + DMCA 1201). No published CVD deadline → L4. security.txt does NOT resolve at either path (403 Akamai) → securityTxt false.” | ||||||
| 66 | IBM ibm.com |
Web form ↗ | policy ↗ | L1 | 2026-06-21 | ▸ |
Contact Only policy text · confidence high
Report via: https://hackerone.com/ibm?type=team · Policy: http://app-06.www.ibm.com/security.txt
“Contact: https://www.ibm.com/trust/security-psirt | Contact: https://hackerone.com/ibm?type=team | Contact: mailto:psirt@us.ibm.com | PSIRT manages Product, Website, Secrets / Tokens Vulnerabilities” | ||||||
| 67 | Eli Lilly lilly.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor web search · confidence high
Report via: https://www.lilly.com/about/contact/cybersecurity-disclosure · Policy: https://www.lilly.com/about/contact/cybersecurity-disclosure
“Product Cybersecurity Coordinated Vulnerability Disclosure Policy. Safe harbor: 'If you comply with this Policy... we will consider your research to be authorized, and not recommend or pursue legal action' + third-party authorization defense. Scope = product cybersecurity (medical devices, SaMD). No statutory carve-outs; timeframes at Lilly's discretion.” | ||||||
| 68 | Merck merck.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/msd · Policy: https://hackerone.com/msd
“Real PUBLIC HackerOne VDP under slug 'msd' (Merck Sharp & Dohme), not 'merck' (404). GraphQL submission_state=open, public_mode, scopes *.merck.com + *.msd.com. Own page merck.com/responsible-vulnerability-disclosure-program/ directs to hackerone.com/msd. Safe harbor + explicit authorization: 'Any activities conducted in a manner the Company deems consistent with this policy will be considered authorized conduct and we will not initiate legal action against you...'. No CFAA/DMCA/ToS carve-out, no deadline → L3. Prior directory-L2 was wrong handle.” | ||||||
| 69 | Nationwide nationwide.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence high
Report via: https://www.nationwide.co.uk/help/fraud-and-security/report-security-vulnerability · Policy: https://www.nationwide.co.uk/help/fraud-and-security/report-security-vulnerability
“vulnerabilitydisclosure@nationwide.co.uk | You must not: Break any applicable law or regulations. Access unnecessary, excessive or significant amounts of data. Modify data in Nationwide's systems or services. | Submissions we won't respond to: Vulnerabilities relating to systems, websites or apps which are not owned or controlled by us. | We do not offer financial compensation or any other form of reward for submissions. | By emailing or providing a disclosure to us, you agree to our terms. | We will review all submissions that meet the requirements listed on this page.” | ||||||
| 70 | Broadcom broadcom.com |
PSIRT ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP web search · confidence high
Report via: symantec.psirt@broadcom.com · Policy: https://www.broadcom.com/support/security-center/vulnerability-management
“Product Security Center with per-product-line PSIRT email reporting. Symantec PSIRT symantec.psirt@broadcom.com ('confirm receipt within three business days', ISO 29147); VMware PSIRT vmware.psirt@broadcom.com. Real VDP with submission method/process, no legal safe-harbor commitment. (hackerone.com/broadcom is a directory stub.)” | ||||||
| 71 | Delta Air Lines delta.com |
Email ↗ | policy ↗ | L1 | 2026-06-21 | ▸ |
Contact Only web search · confidence high
Report via: ResponsibleDisclosure@delta.com · Policy: https://www.delta.com/us/en/legal/vulnerability-disclosure-guidelines
“security.txt at delta.com/security.txt (ROOT path, not /.well-known/ which 404s) → Contact: ResponsibleDisclosure@Delta.com, Policy: VDP guidelines page. NO safe harbor — 'Delta reserves all legal rights in the event of your noncompliance... to pursue legal action'; requires compliance with Delta's Terms of Use. 5-business-day ack.” | ||||||
| 72 | Publix Super Markets publix.com |
Email ↗ | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
Report via: DataProtectionTeam@publix.com
“No researcher channel. security.txt 404 both paths/hosts. HackerOne 'Team does not exist'. Bugcrowd /engagements/publix 404. Synack no DNS. corporate.publix.com is a SPA catch-all (every path incl. nonsense returns same 200 body, no VDP). Prior 'none' confirmed.” | ||||||
| 73 | Pfizer pfizer.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/pfizer · Policy: https://hackerone.com/pfizer
“Real PUBLIC HackerOne VDP (GraphQL submission_state=open, public_mode). Promissory safe harbor: 'Pfizer will not initiate legal action against you for any security research activities... conducted in a manner consistent with this policy.' But testing NOT authorized: 'this policy does not... authorize or encourage any actions...' + 'Do not perform automated scanning or testing.' No CFAA/DMCA/ToS carve-out, no deadline → L3. Prior L1 undercounted.” | ||||||
| 74 | TD Synnex tdsynnex.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No researcher channel. security.txt 404. HackerOne tdsynnex NOT_FOUND; legacy techdata/synnex are UNCLAIMED community stubs (GraphQL state=null, 'community-curated security page documents any known process...'). Bugcrowd engagements x3 404. Synack no DNS. Own /security + /responsible-disclosure 404. Prior 'none' confirmed.” | ||||||
| 75 | ConocoPhillips conocophillips.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No researcher channel. /.well-known/security.txt 404; /security.txt returns 200 but is the SPA HTML shell (not a real file). HackerOne 'conocophillips' is an UNCLAIMED community stub (GraphQL state=null). Bugcrowd 404. Synack no DNS. Own security page describes internal IT/OT program only (no external report path). Prior 'none' confirmed.” | ||||||
| 76 | Galaxy Digital galaxy.com |
security.txt ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: security@galaxy.com
“security.txt at ROOT /security.txt (200): 'Contact: mailto:security@galaxy.com / Expires: 2025-09-30' (expired but still served). NOT at /.well-known/ (404). No Policy line, no scope, no safe harbor. No dedicated security/disclosure page; no HackerOne/Bugcrowd/Synack. Bare contact → L1 confirmed.” | ||||||
| 77 | AbbVie abbvie.com |
Web form ↗ | policy ↗ | L1 | 2026-06-21 | ▸ |
Contact Only web search · confidence high
Report via: https://cvd.abbvie.com/ · Policy: https://cvd.abbvie.com/
“Coordinated Vulnerability Disclosure portal at cvd.abbvie.com (web form). SCOPE LIMITED to AbbVie Medical Devices / SaMD, NOT the corporate abbvie.com web property. No safe harbor; submissions deemed non-confidential. 5-business-day ack. (hackerone.com/abbvie is private/invite-only.)” Source: https://cvd.abbvie.com/ | ||||||
| 78 | Prudential Financial prudential.com |
HackerOne ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/prudential-financial · Policy: https://hackerone.com/prudential-financial
“LIVE HackerOne VDP (GraphQL: state=public_mode, submission=open, scope *.prudential.com). Safe Harbor: 'Any activities conducted in a manner consistent with this Policy and within the Policy's scope will be considered authorized conduct by Prudential, including under the Computer Fraud and Abuse Act, the DMCA, and other applicable computer use laws such as Cal. Penal Code 502(c).' 'reasonable amount of time to resolve' but no numeric deadline → L4. Prior 'none' was WRONG.” | ||||||
| 79 | TJX tjx.com |
security.txt ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: soc-sectxt@tjx.com
“security.txt exists (live WAF-blocked 403; via Wayback raw): 'Contact: mailto:soc-sectxt@tjx.com / Expires: 2026-04-16'. Contact only — no scope, no policy, no safe harbor. hackerone.com/tjx is an empty community-curated stub (GraphQL state=null). L1 confirmed.” | ||||||
| 80 | Performance Food pfgc.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No public reporting channel. security.txt 404 both paths. No HackerOne team (GraphQL NOT_FOUND). No Bugcrowd (404). No Synack. Only IR contact + generic ToU 'notify of any breach' clause. Prior 'none' confirmed.” | ||||||
| 81 | United Airlines united.com |
Bugcrowd ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor web search · confidence medium
Report via: bugbounty@united.com · Policy: https://www.united.com/ual/en/us/fly/contact/vdppolicy.html
“security.txt at /.well-known/ HTTP 200: 'Contact: https://bugcrowd.com/united-vdp / Contact: mailto:bugbounty@united.com / Policy: https://www.united.com/ual/en/us/fly/contact/vdppolicy.html'. Public Bugcrowd VDP (first airline VDP) under Bugcrowd standard disclosure terms (safe harbor for in-scope good-faith research). Triple statutory carve-out could not be confirmed (united.com policy page WAF-blocked) → L3, medium confidence.” | ||||||
| 82 | Oracle oracle.com |
Email ↗ | policy ↗ | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: secalert_us@oracle.com · Policy: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/disclosure/
“Oracle PSIRT reporting (WAF-blocked; via Wayback): 'If you are not a customer or partner, please email secalert_us@oracle.com.' Disclosure policy restrictive: 'Oracle does not distribute exploit code... for vulnerabilities in our products.' No testing authorization, no safe harbor, no carve-out → contact/PSIRT-email only = L1. hackerone.com/oracle stub; bugcrowd.com/oracle is /h/ private portal (control-tested). Prior L1 confirmed.” | ||||||
| 83 | Cisco Systems cisco.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP policy text · confidence medium
Report via: https://bugcrowd.com/ciscomeraki · Policy: https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html
“The Cisco PSIRT is a dedicated, global team that receives, investigates, and publicly reports information about security vulnerabilities and issues related to Cisco products and services. | Cisco welcomes reports from independent researchers, industry organizations, vendors, customers, and other sources concerned with product or network security. | Throughout the investigative process, the Cisco PSIRT strives to work collaboratively with the incident reporter to assess the nature of the vulnerability, gather required technical information, and determine appropriate remedial action. | The Cisco PSIRT asks incident reporters to maintain strict confidentiality until complete resolutions are available for customers and have been published by the Cisco PSIRT on the Cisco website through the appropriate coordinated disclosure. | The Cisco PSIRT aligns its practices with ISO/IEC 29147:2018, which are guidelines for disclosure of potential vulnerabilities established by the International Organization for Standardization.” | ||||||
| 84 | HP hp.com |
PSIRT ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: https://enable.hp.com/potentialsecurityvulnerability-report · Policy: https://enable.hp.com/potentialsecurityvulnerability-report
“HP PSRT report page (enable.hp.com/potentialsecurityvulnerability-report) — live web form, product-scoped dropdown, 'HP will acknowledge receipt of the submission within two business days and begin investigating.' No legal/safe-harbor language → real VDP, L2. HP's Bugcrowd bounty is PRIVATE/invite-only (/h/hp). Prior L1 upgraded to L2.” | ||||||
| 85 | Charter Communications corporate.charter.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No verified public channel across corporate.charter.com, charter.com, spectrum.com. hackerone.com/chartercom is an empty community-curated stub (GraphQL state=null, no scopes). No security.txt anywhere. bugcrowd.com/spectrum is /h/ catch-all (control-tested). Prior 'none' confirmed.” | ||||||
| 86 | American Airlines aa.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor web search · confidence high
Report via: https://hackerone.com/aa · Policy: https://hackerone.com/aa
“Managed HackerOne VDP (no bounty). Scope *.aa.com + regional carriers. Safe harbor: 'Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party... we will take steps to make it known that your actions were conducted in compliance with this policy.' Authorizes testing + no legal action (L4). No statutory carve-outs named, no CVD deadline. Verified via real-Chrome render.” Source: https://hackerone.com/aa | ||||||
| 87 | Tyson Foods tysonfoods.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel on any surface. security.txt 404 (apex+www both paths). Only security-adjacent page is financial/ethics disclosures. HackerOne /tyson + /tysonfoods no real program. Bugcrowd 404. Synack refused. UpGuard scan confirms no security.txt/VDP. Prior 'none' confirmed.” | ||||||
| 88 | Intel intel.com |
PSIRT ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor web search · confidence high
Report via: secure@intel.com · Policy: https://www.intel.com/content/www/us/en/security-center/vulnerability-handling-guidelines.html
“security.txt at /.well-known/ + root (Canonical https://www.intel.com/security.txt; Policy -> vulnerability-handling-guidelines.html). PSIRT secure@intel.com + Intel Bug Bounty via Intigriti. Safe harbor in bug-bounty terms: 'Intel will not initiate a lawsuit or law enforcement investigation against you in response to your report.' No explicit CFAA/DMCA/ToS carve-out → L3.” | ||||||
| 89 | Enterprise Products enterpriseproducts.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. Footer/nav have no security/disclosure link; Contact Us is operational/investor only. security.txt 404 both paths. HackerOne enterpriseproducts + enterprise-products 404 (no stub). Bugcrowd 404. Synack refused. Prior 'none' confirmed.” | ||||||
| 90 | Ingram Micro ingrammicro.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. hackerone.com/ingrammicroinc is an empty community stub (real-Chrome: 'There are no known guidelines...' + 'not affiliated', no submit). Bugcrowd 404. Synack NXDOMAIN. No security.txt (WAF). Trust Centre FAQ directs to general support form, no security scope. Prior 'none' confirmed.” | ||||||
| 91 | General Dynamics gd.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No VDP at gd.com. security.txt 301→404. Homepage/contact/sitemap no security refs. HackerOne 'generaldynamicssharedr' is empty stub (GraphQL all-null); generaldynamics/general-dynamics/gdit team does not exist. Bugcrowd 404. Synack DNS-fail. Business units publish only DFARS supplier incident reporting (not a researcher VDP). Prior 'none' confirmed.” | ||||||
| 92 | Uber Technologies uber.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/uber · Policy: https://hackerone.com/uber?view_policy=true
“Real HackerOne bug bounty. Safe harbor (promissory): 'If you have made a good faith effort to abide by these Program Terms, we will not initiate or recommend legal action against you, and if a third party initiates legal action, we will make it known that your activities were conducted pursuant to the Bug Bounty Program.' But NO testing authorization ('Actions taken beyond this are not authorized'), NO CFAA/DMCA in the 29k-char rendered policy, and policy REQUIRES ToS compliance (no exemption), no disclosure deadline → L3 (HackerOne's platform Gold-Standard language NOT adopted into Uber's text). Prior L1 undercounted; not over-called to L4.” | ||||||
| 93 | USAA usaa.com |
Web form ↗ | policy ↗ | L1 | 2026-06-21 | ▸ |
Contact Only policy text · confidence high
Report via: https://bugcrowd.com/usaa · Policy: http://usaa.com/.well-known/security.txt
“Contact: https://bugcrowd.com/engagements/usaa | Contact: mailto:disclosure@usaa.com | Policy: https://bugcrowd.com/usaa” | ||||||
| 94 | TIAA tiaa.org |
HackerOne ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: security@tiaa.org · Policy: https://www.tiaa.org/public/support/security-center
“TIAA security-center page → HackerOne embedded form rendering the full 'TIAA Vulnerability Disclosure Policy'. Safe harbor: 'we consider this research conducted under this policy to be: Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you...; Authorized concerning any relevant anti-circumvention laws...; Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP)... and we waive those restrictions on a limited basis.' Scope (*.tiaa.org, *.tiaa-cref.org, *.nuveen.com). No published public-disclosure deadline → L4. Prior 'none' was a major miss.” | ||||||
| 95 | Liberty Mutual Insurance libertymutualgroup.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No researcher channel. HackerOne (liberty_mutual/libertymutual/liberty-mutual all 404). Bugcrowd 404. Synack NXDOMAIN. security.txt 404 (libertymutual.com) / Akamai 403 with no archived file (libertymutualgroup.com). Only 'Security Policy' page is customer-data protection, no researcher reporting. Prior 'none' confirmed.” | ||||||
| 96 | Travelers travelers.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor policy text · confidence high
Report via: https://www.synack.com/vdp/travelers/ · Policy: https://www.synack.com/vdp/travelers/
“Synack commits that, if we conclude, in our sole discretion, that a security vulnerability submitted through our Site complies with the Terms of Use, the applicable Scope and Rules of Engagement and the applicable Responsible Disclosure Guidelines, Synack will not bring a private action against you or refer the matter for public inquiry. | The following web applications are in scope: *.travelers.com | If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. | Adhere to these Guidelines and the Rules of Engagement and Scope, and do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of Travelers' information and systems.” | ||||||
| 97 | Bristol-Myers Squibb bms.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne GraphQL 'bms' = Team does not exist (the 200 is an SPA shell); 3 other slugs 404. Bugcrowd 404. Synack NXDOMAIN. security.txt 404 (the Wayback 200 is an Incapsula WAF challenge page, not a real file). Only privacy (dpo@bms.com) + compliance Integrity Line. Prior 'none' confirmed.” | ||||||
| 98 | Coca-Cola coca-cola.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor policy text · confidence high
Report via: https://bugcrowd.com/coca-cola · Policy: https://www.intigriti.com/programs/tccc/coca-cola/detail
“Safe harbour for researchers is applied | with the exception of what is listed as explicitly out-of-scope you are welcome and encouraged to submit impactful findings on any asset you can attribute to The Coca-Cola Company or our brands! | Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)” | ||||||
| 99 | Nike about.nike.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: infosec@nike.com · Policy: https://www.nike.com/help/a/responsible-disclosure
“Real first-party VDP (full text read from __NEXT_DATA__). Scope + submission form (nike.com/help/disclosure) + prohibited-methods list. Not a bounty. CVD timeline present: 'We're committed to patching in-scope vulnerabilities in 90 days or less' + 90-day confidentiality. Safe harbor only soft ('open dialogue... without fear of reprisal') — NO explicit non-pursuit, NO testing authorization, NO CFAA/DMCA/ToS carve-out → L2. (hackerone.com/nike is an empty unclaimed stub, does not count.) Prior L2 confirmed.” | ||||||
| 100 | Massachusetts Mutual massmutual.com |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP web search · confidence high
Report via: responsible.disclosure@massmutual.com · Policy: https://www.massmutual.com/protecting-your-information/responsible-disclosure-policy
“Self-hosted Responsible Disclosure Policy; report via responsible.disclosure@massmutual.com. Structured RDP rules + scope, but NO safe harbor and explicitly hostile: 'MassMutual expressly reserves all rights afforded to it, by law or in equity.' Prohibits public disclosure without consent.” | ||||||
🇦🇺 Australia · snapshot 2026-06-21 · 100 companies · graded against the disclose.io Maturity Model
| # | Company | Report | Policy | Disclose.io Maturity Level | Last verified | |
|---|---|---|---|---|---|---|
| 1 | BHP Group bhp.com |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: cybersecurity@bhp.com · Policy: https://www.bhp.com/responsible-disclosure
“First-party responsible-disclosure policy (bhp.com/responsible-disclosure). Scope + submit to cybersecurity@bhp.com, but RESTRICTS testing: 'Do not attempt to exploit any potential vulnerabilities'; 'use of scanners or automated tools' prohibited; 'BHP does not provide any form of compensation'. No safe harbor, no authorization, no carve-out, no deadline → L2. HackerOne bhp NOT_FOUND/bare; Bugcrowd 404; no valid security.txt.” | ||||||
| 2 | Commonwealth Bank of Australia commbank.com.au |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: vulnerability@cba.com.au · Policy: https://www.commbank.com.au/support/security/vulnerability-disclosure-program.html
“Self-authored VDP (scope + email submit to vulnerability@cba.com.au + prohibited activities). Explicit no-safe-harbor: 'CommBank does not waive any rights or claims with respect to such activities.' No non-pursuit, no authorization, no carve-out, no timeline → L2. Real text/plain security.txt at /.well-known/ (Contact: vulnerability@cba.com.au). HackerOne commonwealthbank null stub.” | ||||||
| 3 | Westpac Banking Corporation westpac.com.au |
Bugcrowd ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/engagements/westpac-vdp-pro · Policy: https://bugcrowd.com/engagements/westpac-vdp-pro
“Public Bugcrowd VDP (visibility_public, open, 37 vulns, Safe-harbor status 'full'). Brief Safe Harbor verbatim: 'Authorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy; Exempt from the Digital Millennium Copyright Act (DMCA)... circumvention of technology controls; Exempt from restrictions in our Terms & Conditions... we waive those restrictions on a limited basis.' Explicit testing authorization + all three carve-outs → L4. No numeric disclosure deadline → not L5. (Confirmed by two independent reads; the first under-graded L2 when the brief legalese was gated.)” | ||||||
| 4 | National Australia Bank nab.com.au |
Bugcrowd ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/engagements/nationalaustraliabankog · Policy: https://www.nab.com.au/about-us/security
“Bugcrowd VDP (nationalaustraliabankog), real-Chrome confirmed safe-harbor tier = 'Partial safe harbor' (Bugcrowd partial = a limited goodwill non-pursuit commitment). Promissory non-pursuit, testing NOT explicitly authorized, no statutory carve-out, no disclosure deadline -> L3 (consistent with Telstra/ANZ partial-tier programs). HackerOne nab null stub.” | ||||||
| 5 | ANZ Group Holdings anz.com.au |
Bugcrowd ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/engagements/anz-vdp · Policy: https://bugcrowd.com/engagements/anz-vdp
“Bugcrowd VDP (anz-vdp), real-Chrome confirmed safe-harbor tier = 'Partial safe harbor' (limited goodwill non-pursuit commitment). Promissory non-pursuit, testing NOT explicitly authorized, no statutory carve-out, no deadline -> L3 (consistent with Telstra/NAB partial-tier programs).” | ||||||
| 6 | Wesfarmers wesfarmers.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No researcher channel on the parent domain. /security-privacy is privacy-only; FY22 cyber page is internal practices only. security.txt both paths + www → HTML 404 (no Contact:). HackerOne wesfarmers null stub. Bugcrowd /engagements/wesfarmers 404. Subsidiaries (Bunnings/Kmart) excluded per parent scope → L0.” | ||||||
| 7 | Macquarie Group macquarie.com |
Bugcrowd ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/engagements/macquarie-group-vdp · Policy: https://bugcrowd.com/engagements/macquarie-group-vdp
“Real-Chrome (Interceptor) read of the Bugcrowd brief — full disclose.io safe harbor, verbatim: 'Safe Harbor: When conducting vulnerability research according to this policy, we consider this research to be: Authorized in accordance with the Computer Fraud and Abuse Act (CFAA)... we will not initiate or support legal action...; Exempt from the Digital Millennium Copyright Act (DMCA)... circumvention of technology controls; Exempt from restrictions in our Terms & Conditions... we waive those restrictions on a limited basis.' Testing authorized + 3 carve-outs (CFAA/DMCA/ToS) -> L4. 'Does not allow disclosure' -> no L5. (Earlier WebFetch could not render this JS/auth-gated brief; confirmed live in real Chrome 2026-06-21.)” | ||||||
| 8 | Newmont Corporation newmont.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. Governance/ethics page has only a general Integrity Helpline (not a VDP). HackerOne newmont empty shell. Bugcrowd /engagements/newmont 404. security.txt → 'Invalid key' WAF string (no Contact:) / 404. → L0.” | ||||||
| 9 | Goodman Group goodman.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne GraphQL goodman/goodmangroup NOT_FOUND. Bugcrowd /engagements/{goodman,...} 404 (bare /goodman = /h/ catch-all only). security.txt 403 WAF JS-challenge / Next.js 404; Wayback never archived. No VDP/PSIRT page. → L0.” | ||||||
| 10 | Rio Tinto riotinto.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“hackerone.com/riotinto is an UNCLAIMED community/external directory stub, NOT a real program: GraphQL submission_state:null/policy:null, and the real-Chrome page renders verbatim 'There are no known guidelines for reporting potential security vulnerabilities' (HackerOne's text for an unconfigured directory listing). No own-site security.txt or policy either. No real researcher channel -> L0. (Confirmed real Chrome 2026-06-21.)” | ||||||
| 11 | Fortescue fortescue.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No researcher channel. security.txt 404 (fortescue.com + www; fmgl.com.au redirects to 404). HackerOne fortescue 404. Bugcrowd /engagements/fortescue(-metals) 404. Only reporting path is the 'Speak Up' EthicsPoint whistleblower hotline (scoped to misconduct, not security) → does not qualify. → L0.” | ||||||
| 12 | Telstra Group telstra.com.au |
Bugcrowd ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/engagements/telstra-vdp · Policy: https://bugcrowd.com/engagements/telstra-vdp
“Real active Bugcrowd VDP (brief changelog 2025-10-09). Authorizes scoped testing: 'Testing is only authorised on the targets listed as in scope.' safeHarborStatus={status:'partial', 'limited goodwill statement about not pursuing legal action'} — promissory non-pursuit present but limited, NO statute-specific carve-out (no Criminal Code/anti-circumvention/ToS), no disclosure deadline (disclosure prohibited) → L3. HackerOne telstra null stub. No valid security.txt. Telstra's own hub links to the Bugcrowd engagement.” | ||||||
| 13 | CSL Limited csl.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel for CSL Limited (biotech, csl.com). security.txt 404 (apex+www). /disclosures is legal/financial; data-protection page is internal gov only. TRAP: hackerone.com/csl + csl-group.com VDP belong to a DIFFERENT company (CSL Group M2M/IoT), excluded. -> L0.” | ||||||
| 14 | Woodside Energy Group woodside.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (all paths). hackerone.com/woodsideenergy is an UNCLAIMED external directory stub (is_external_program:true, policy:null, claimed:false; GraphQL submission_state:null) -> does not count. Bugcrowd /engagements/woodside(-energy) 404. -> L0.” | ||||||
| 15 | Transurban Group transurban.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt absent (HTML homepage / 404 at all paths; Wayback empty). hackerone.com/transurban 404. Bugcrowd /engagements/transurban + bare 404. /privacy lists only privacy + tolling emails. -> L0.” | ||||||
| 16 | Woolworths Group woolworthsgroup.com.au |
Email ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: vulnerabilitydisclosure@woolworths.com.au
“Company page: 'email vulnerabilitydisclosure@woolworths.com.au' — contact only, no policy/scope. Testing NOT authorized: 'does not condone... testing activities that violate laws and regulations.' No safe harbor. HackerOne woolworthslimited exists but empty policy/scope (not confirmable open). No security.txt. -> L1.” | ||||||
| 17 | QBE Insurance Group qbe.com |
Email ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: security@qbe.com · Policy: https://www.qbe.com/responsible-disclosure-program
“Company Responsible Disclosure Program. Non-pursuit: 'we will not take legal action against security researchers acting in good faith... provided that all such potential security vulnerabilities are discovered and reported strictly in accordance with this Responsible Disclosure Program.' Submit to security@qbe.com. Testing NOT affirmatively authorized (only services 'to which you have authorised access'); no carve-out, no deadline -> L3. (read via Wayback raw + regional mirrors). HackerOne qbe empty stub.” | ||||||
| 18 | Aristocrat Leisure aristocrat.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt redirects to HTML 404 (aristocrat.com + aristocratgaming.com 200-but-HTML). HackerOne GraphQL NOT_FOUND for 6 slug variants (the /aristocrat 200 is SPA shell). Bugcrowd /engagements/ 404 x4 (bare -> /h/ catch-all). Only Privacy/Disclosure/Whistleblower policies. -> L0.” | ||||||
| 19 | Coles Group colesgroup.com.au |
Bugcrowd ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/engagements/coles-vdp-pro · Policy: https://bugcrowd.com/engagements/coles-vdp-pro
“Real-Chrome read of the Bugcrowd brief (coles-vdp-pro) — full disclose.io safe harbor renders verbatim: 'Authorized in accordance with the Computer Fraud and Abuse Act (CFAA)... we will not initiate or support legal action...; Exempt from the Digital Millennium Copyright Act (DMCA)...; Exempt from restrictions in our Terms & Conditions... we waive those restrictions.' Testing authorized + 3 carve-outs -> L4 (the full-safe-harbor text renders only for full-tier engagements; verified program-specific, not boilerplate). 'Does not allow disclosure' -> no L5. (Earlier WebFetch/Wayback could not render the full section; confirmed in real Chrome 2026-06-21.)” | ||||||
| 20 | Northern Star Resources nsrltd.com |
Email ↗ | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
Report via: licensing@nsrltd.com
“No channel. No security/disclosure page; contact-us has only general emails. HackerOne 3 slugs empty/404. Bugcrowd /engagements/ 404. security.txt 404 (apex+www). -> L0.” | ||||||
| 21 | Brambles brambles.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel (brambles.com + chep.com). Only a 'Speak Up' ethics hotline + privacy breach notice. TRAP: brmbl.io 'Bramble' VDP is a DIFFERENT company (GitLab fork), excluded. HackerOne /brambles 404, /chep empty. Bugcrowd 404. security.txt 404 both domains. -> L0.” | ||||||
| 22 | Evolution Mining evolutionmining.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. Contact page has only office phones, registry, whistleblower line. security.txt 404 both paths. HackerOne 2 slugs 404. Bugcrowd 3 slugs 404. -> L0.” | ||||||
| 23 | Amcor amcor.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt clean 404 x3. HackerOne /amcor 404. Bugcrowd /engagements/amcor + bare 404. Governance page lists 26 policies, none a VDP. -> L0.” | ||||||
| 24 | Santos santos.com |
Bugcrowd ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: security@santos.com · Policy: https://bugcrowd.com/santos-vdp
“Valid text/plain security.txt → Bugcrowd santos-vdp (open). Authored safe harbor: 'Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate and legal action against you...' + 'Testing is only authorized on the targets listed as in scope.' No named statutory carve-out, no DMCA/ToS, no deadline -> L3. HackerOne santos empty placeholder.” | ||||||
| 25 | Computershare computershare.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (apex+www, no Wayback capture). HackerOne /computershare 404. Bugcrowd /engagements/computershare + bare 404. Site describes internal/contracted pentesting only; the one security email is for account fraud. → L0.” | ||||||
| 26 | Suncorp Group suncorpgroup.com.au |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: vulnerability@suncorp.com.au · Policy: https://www.suncorp.com.au/vulnerability-disclosure-program.html
“Company-authored VDP (scope + email submit to vulnerability@suncorp.com.au). No safe harbor — prohibits automated tools and reserves rights: 'Suncorp reserves the right to act against individuals engaged in any of the activities listed above.' No carve-out, no timeline → L2. No security.txt; no HackerOne/Bugcrowd. (VDP on customer site suncorp.com.au, not corporate.)” | ||||||
| 27 | Scentre Group scentregroup.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“HackerOne 'scentregroup' exists in directory but is NOT public/open: GraphQL submission_state:null/state:null/policy:null (control: a public program returns submission_state:'open'). All Wayback snapshots show only directory boilerplate, no authored policy. No public gradeable policy → null/L0. Bugcrowd 404; security.txt 404.” | ||||||
| 28 | Pilbara Minerals pls.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. pilbaraminerals.com.au 301→pls.com. No security/responsible-disclosure page; governance lists 25 policies, none for vuln disclosure. Only security-adjacent contact is a privacy officer. security.txt 404 (both domains). HackerOne/Bugcrowd 404. → L0.” | ||||||
| 29 | Insurance Australia Group iag.com.au |
Email ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence medium
Report via: cybersecurity@iag.com.au
“Only authored artifact was a security.txt (contact cybersecurity@iag.com.au, 'No paid bounties currently offered') — contact only, no scope/policy. BUT it EXPIRED 1 Jan 2025 and now 404s (live Akamai 403; Wayback 404 since 2025-05). HackerOne /iag is a reserved null stub. → L1 (on the historical contact; arguably 'removed' now). confidence medium (archived, not live).” | ||||||
| 30 | Origin Energy originenergy.com.au |
Bugcrowd ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/engagements/originenergy-og1 · Policy: https://bugcrowd.com/engagements/originenergy-og1
“Valid text/plain security.txt → Bugcrowd engagement originenergy-og1 (active, changelog 2026-03-30) + digitalsecurity@originenergy.com.au. Brief Safe Harbor verbatim: 'we consider this research to be: Authorized in accordance with the Computer Fraud and Abuse Act (CFAA)... we will not initiate or support legal action...; Exempt from the Digital Millennium Copyright Act (DMCA)...; Exempt from restrictions in our Terms & Conditions... we waive those restrictions on a limited basis.' Testing authorized + 3 carve-outs → L4. No disclosure deadline → not L5. (Carve-out cites US CFAA/DMCA — Bugcrowd boilerplate — mapped to cfaaCarveout per instruction; page may footnote US-law references.)” | ||||||
| 31 | South32 south32.net |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne GraphQL NOT_FOUND (south32, south-32). Bugcrowd /engagements/south32 404. security.txt 404/empty (south32.net + south32.com); Wayback 0 snapshots. -> L0.” | ||||||
| 32 | REA Group rea-group.com |
Bugcrowd ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: security-vulnerability@rea-group.com · Policy: https://www.rea-group.com/security/
“REA security page → public Bugcrowd bug bounty (rea-mbb-og, live, changelog 2026-06-01). Authored non-pursuit: 'Not pursue legal action related to your discovery and reporting of the vulnerability (in relation to any non-compliance... we reserve all of our legal rights).' Published timeline: confidentiality 'no less than 90 days'. NO explicit testing authorization, NO named statutory carve-out -> L3 (L5 needs L4 first). Carve-outs graded from REA's authored text only.” | ||||||
| 33 | Lynas Rare Earths lynasrareearths.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 HTML both paths. HackerOne GraphQL NOT_FOUND (6 slugs). Bugcrowd /engagements/ 404 x2. /contact has only IR/media/general; whistleblower only. -> L0.” | ||||||
| 34 | Pro Medicus promed.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 HTML across promed.com.au/promedicus.com/visage(imaging).com. HackerOne GraphQL NOT_FOUND (promedicus, pro-medicus, visage). Bugcrowd /engagements/ 404 x3. Privacy only. -> L0.” | ||||||
| 35 | Seven Group Holdings sghl.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 HTML both paths; Wayback none. HackerOne GraphQL NOT_FOUND (4 slugs). Bugcrowd /engagements/ 404 x2. Contact/privacy only; subsidiaries (WesTrac/Coates/Boral/SWM) don't cover parent. -> L0.” | ||||||
| 36 | Washington H Soul Pattinson and Company soulpatts.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 HTML both paths; Wayback 404 since 2024. HackerOne GraphQL NOT_FOUND (soulpatts, whsp, soulpattinson). Bugcrowd /engagements/ 404 x4. /privacy only (also checked new name WHSP Holdings). -> L0.” | ||||||
| 37 | James Hardie Industries jameshardie.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 HTML (jameshardie.com + .com.au, both paths). HackerOne 3 slugs 404. Bugcrowd /engagements/ 404 x2. Only ASX/SEC disclosure policy + ethics hotline. -> L0.” | ||||||
| 38 | Qantas Airways qantas.com |
Bugcrowd ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: qantas-vdp-ess@submit.bugcrowd.com · Policy: https://bugcrowd.com/engagements/qantas-vdp-ess
“Valid text/plain security.txt (both paths) → open Bugcrowd VDP (qantas-vdp-ess, In progress since Nov 2025). Qantas-authored security.txt grants NO authorization — lists ONLY prohibitions: 'The following activities are strictly prohibited and are not authorised by Qantas Group under any circumstances...'. Only safe-harbor framing is Bugcrowd boilerplate (not credited). '21 days validation' is an SLA, not a deadline. HackerOne /qantas unaffiliated stub. -> L2.” | ||||||
| 39 | BlueScope Steel bluescope.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (bluescope.com HTML; bluescopesteel.com.au plain 404). HackerOne 4 slugs 404. Bugcrowd /engagements/ 404 x4. Only privacy + ethics emails. -> L0.” | ||||||
| 40 | Mineral Resources mineralresources.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 Next.js HTML (4 URLs). HackerOne minres/mineralresources absent (bounty-targets-data 457 handles, no match). Bugcrowd 404 x2. Only 'MinRes Integrity Assist' whistleblower. -> L0.” | ||||||
| 41 | APA Group apa.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 both paths; sitemap has no security URLs. HackerOne 'apa' = American Psychological Association (different co); 'apagroup' 404. Bugcrowd 404 x2. Only whistleblower hotline. -> L0.” | ||||||
| 42 | Medibank Private medibank.com.au |
Email ↗ | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
Report via: mpl_secops_alerts@medibank.com.au
“No researcher channel (despite the 2022 mega-breach). security.txt 301→unreachable internal AEM host (text/html, no Contact); root 404. /security/ + /cybersecurity 404. HackerOne 2 slugs 404. Bugcrowd 404 x3. Own guidance points public to ScamWatch/ACSC (consumer fraud, not researcher VDP). -> L0.” | ||||||
| 43 | WiseTech Global wisetechglobal.com |
security.txt ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: csirt@wisetechglobal.com
“Valid PGP-signed text/plain security.txt: 'Contact: mailto:csirt@wisetechglobal.com' + Expires 2026-11-27. No Policy field, no scope, no safe harbor. /information-security/ page has no reporting channel. Contact-only → L1.” | ||||||
| 44 | Xero xero.com |
Bugcrowd ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/engagements/xero-vdp-pro · Policy: https://www.xero.com/us/security/vulnerability-disclosure/
“Xero's OWN authored VDP policy: research 'authorized in accordance with the Computer Fraud and Abuse Act (CFAA)... we will not initiate or support legal action...'; 'exempt from the Digital Millennium Copyright Act (DMCA)...'; 'exempt from restrictions in our terms of use... we waive those restrictions on a limited basis.' Authorization + all 3 carve-outs → L4. No disclosure deadline → not L5. Submissions via Bugcrowd xero-vdp-pro (open).” | ||||||
| 45 | The Lottery Corporation thelotterycorporation.com |
Email ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: security@thelotterycorporation.com · Policy: https://www.thelotterycorporation.com/security
“Authored Responsible Disclosure Statement. Non-pursuit: 'Not pursue legal action related to your discovery and reporting of the vulnerability...'. Testing NOT authorized: 'does not give you permission to breach any laws...'. 90-day confidentiality timeline. No carve-out → L3 (L5 needs L4). Valid PGP security.txt.” | ||||||
| 46 | Vicinity Centres vicinity.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. No VDP page (privacy+T&C only). HackerOne GraphQL NOT_FOUND (3 slugs). Bugcrowd 404. security.txt redirect-loop / CF 403 (no real text/plain file); Wayback none. -> L0.” | ||||||
| 47 | ALS Limited alsglobal.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne GraphQL NOT_FOUND (4 slugs). Bugcrowd 404. security.txt → site HTML 404 both paths; Wayback none. Only Continuous Disclosure (financial) + privacy. -> L0.” | ||||||
| 48 | Charter Hall Group charterhall.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne GraphQL NOT_FOUND (3 slugs). Bugcrowd 404 x3. security.txt 404 HTML both paths (apex+www); Wayback none. Privacy + contact only. -> L0.” | ||||||
| 49 | NextDC nextdc.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 both paths. Security pages cover only physical/ISO/SOC/PCI compliance. HackerOne /nextdc 404. Bugcrowd 404. -> L0.” | ||||||
| 50 | Orica orica.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt = Cloudflare JS challenge (403, no text/plain); Wayback none. HackerOne /orica bare page, absent from datasets. Bugcrowd 404. Only privacy/governance/whistleblower. -> L0.” | ||||||
| 51 | CAR Group cargroup.com |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: security@carsales.com.au · Policy: https://www.carsales.com.au/info/responsible-disclosure-program/
“carsales (CAR Group) own Responsible Disclosure page: scope + 'send an email to security@carsales.com.au'. No safe harbor — reserves legal rights: 'we will put the handbrake on, cease your participation... and reserve all our legal rights.' Prohibits ToS breach (not waive), no testing auth, no carve-out, no timeline -> L2. HackerOne carsales = null stub (does not count).” | ||||||
| 52 | Stockland stockland.com.au |
Email ↗ | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence medium
Report via: DL_IT_TS@stockland.com.au
“HackerOne lists a 'Stockland | VDP' title but GraphQL team(handle:stockland) returns submission_state:null/policy:null — a null stub that does NOT count (bare client-rendered shell). No own-site page; Bugcrowd 404; security.txt 403 WAF, no Wayback. No confirmed readable channel -> L0.” | ||||||
| 53 | ASX Limited asx.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“Only security page is scam/phishing reporting (hoax@asx.com.au) — fraud infrastructure, not a researcher channel. No VDP/scope/safe harbor. HackerOne GraphQL 'Team does not exist'. Bugcrowd 404 x3. security.txt HTML 404, no Wayback. -> L0.” | ||||||
| 54 | Sonic Healthcare sonichealthcare.com |
Web form ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: https://www.sonichealthcare.com/privacy-and-security/vulnerability-disclosure-policy/ · Policy: https://www.sonichealthcare.com/privacy-and-security/vulnerability-disclosure-policy/
“Company-authored VDP (group + subsidiaries): 'To report a vulnerability, please fill out the below form.' Scope + submission + a coordination/5-day clause, but NO testing authorization and NO non-pursuit/CFAA/DMCA/ToS carve-out -> L2. Has a security.txt + a parallel Bugcrowd sonic-vdp-pro engagement.” | ||||||
| 55 | Technology One technology1.com |
Email ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: security@technology1.com
“'Security and privacy incident reporting': 'Email privacy@technologyonecorp.com or security@technology1.com to notify TechnologyOne of a privacy or security breach.' Customer breach channel only — no researcher VDP, no scope, no safe harbor -> L1. HackerOne NOT_FOUND; Bugcrowd 404; no security.txt.” | ||||||
| 56 | GPT Group gpt.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne 'thegptgroup' is a null stub (GraphQL submission_state:null) — does not count; other slugs NOT_FOUND. Privacy only; security.txt 404 both paths; Bugcrowd 404 x3. -> L0.” | ||||||
| 57 | Greatland Resources greatland.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (greatland.com.au + greatlandgold.com). HackerOne NOT_FOUND (3 slugs). Bugcrowd 404 x3. Privacy only. -> L0.” | ||||||
| 58 | Ramsay Health Care ramsayhealth.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. Only /security page is ISO/NHS data-protection posture (no reporting). security.txt 404 across .com/.com.au/.co.uk. HackerOne NOT_FOUND. Bugcrowd 404. Only privacy officer email. -> L0.” | ||||||
| 59 | Qube Holdings qube.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt clean 404. No security page; privacy only. HackerOne qube + qubeholdings NOT_FOUND (no stub). Bugcrowd 404 x3. (security@qube-rt.com is unrelated Qube Research & Technologies.) -> L0.” | ||||||
| 60 | JB Hi-Fi jbhifi.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (Shopify HTML / size-0). No VDP page. HackerOne NOT_FOUND. Bugcrowd 404 x3. The Good Guys (subsidiary) also none. -> L0.” | ||||||
| 61 | Ampol ampol.com.au |
HackerOne ↗ | policy ↗ | L4 | 2026-06-21 | ▸ |
Full Safe Harbor deep audit · confidence high
Report via: https://www.ampol.com.au/vulnerability-disclosure-policy · Policy: https://www.ampol.com.au/vulnerability-disclosure-policy
“Ampol's own Safe Harbour prose: 'we consider this research conducted under this policy to be: Authorised in view of any applicable anti-hacking law; Authorised in view of relevant anti-circumvention laws...'. Submit via embedded HackerOne form. testingAuthorized + anti-hacking (CFAA-equiv) + anti-circumvention (DMCA-equiv) = L4. No ToS waiver, no deadline. Confirmed by adversarial double-read.” | ||||||
| 62 | Cochlear cochlear.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“Medical-device maker but no researcher VDP. security.txt 404 (3 paths). HackerOne GraphQL NOT_FOUND (3 slugs). Bugcrowd 404. Data Privacy page routes to customer service. -> L0.” | ||||||
| 63 | TPG Telecom tpgtelecom.com.au |
security.txt ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: vulnerability@tpgtelecom.com.au
“Valid security.txt (200 text/plain): 'Contact: mailto:vulnerability@tpgtelecom.com.au / Expires: 2027-01-01'. Contact only, no policy → L1. HackerOne tpg_telecom unclaimed stub (does not count).” | ||||||
| 64 | Atlas Arteria atlasarteria.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne NOT_FOUND (2 slugs). Bugcrowd 404. security.txt 307→SPA HTML; /security + /responsible-disclosure SPA soft-404s. -> L0.” | ||||||
| 65 | Perseus Mining perseusmining.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne NOT_FOUND (2 slugs). Bugcrowd 404. security.txt 404 (no Wayback). 25+ governance policies, none security. -> L0.” | ||||||
| 66 | Aurizon Holdings aurizon.com.au |
Email ↗ | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
Report via: certificate_management@equatetechnologies.com.au
“No channel. hackerone.com/aurizon empty stub (submission_state:null, does not count). Bugcrowd 404 x2. security.txt 404 (aurizon.com.au); aurizon.com is a parked lander. -> L0.” | ||||||
| 67 | Mirvac Group mirvac.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 both paths (genuine). HackerOne /mirvac JS stub (no open program). Bugcrowd 404. Only privacy@mirvac.com. -> L0.” | ||||||
| 68 | Genesis Minerals genesisminerals.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 HTML both paths; Wayback none. HackerOne 2 slugs 404. Bugcrowd 404 x2. Governance has no security terms. -> L0.” | ||||||
| 69 | Challenger Limited challenger.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No live channel. A contact-only security.txt (cyberteam@challenger.com.au) existed 2023→late-2024 but is REMOVED (live 404 HTML; Wayback 404 since 2025-05). No disclosure page (consumer scam tips only). HackerOne /challenger no program. Bugcrowd 404. -> L0.” | ||||||
| 70 | Whitehaven Coal whitehavencoal.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt genuine 404 both paths; Wayback none. HackerOne 3 slugs 404. Bugcrowd 404 x3. Contact page has no security contact. -> L0.” | ||||||
| 71 | Eagers Automotive eagersautomotive.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No verifiable channel. ENTIRE domain returns 403 to all clients incl. real Chrome (hard geo/IP block) — on-site page can't be read but no independently verifiable channel exists. security.txt 403 HTML (no Wayback). HackerOne 4 slugs 404. Bugcrowd 404 x2. -> L0.” | ||||||
| 72 | Dexus dexus.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (apex+www, both paths). HackerOne /dexus empty stub. Bugcrowd 404 x2. Privacy has only an internal breach plan, no reporting mechanism. -> L0.” | ||||||
| 73 | IGO Limited igo.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 both paths (no Wayback). HackerOne GraphQL NOT_FOUND (2 slugs). Bugcrowd 404 x2. /security + /responsible-disclosure 404. Privacy only. -> L0.” | ||||||
| 74 | Worley worley.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (no Wayback). HackerOne GraphQL NOT_FOUND (2 slugs). Bugcrowd 404 x2. Only an internal Information Security Policy (governance, not researcher VDP). -> L0.” | ||||||
| 75 | Endeavour Group endeavourgroup.com.au |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: security@edg.com.au · Policy: https://www.endeavourgroup.com.au/vulnerability-disclosure-policy
“Real published VDP: scope ('independent security researchers for any internet facing systems or SaaS') + submit to security@edg.com.au. NO safe harbor — reserves rights: 'In the event that a security vulnerability is not reported in accordance with this policy, we reserve all of our legal rights.' No testing auth, no carve-out, no deadline -> L2.” | ||||||
| 76 | Capricorn Metals capmetals.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404. HackerOne GraphQL NOT_FOUND. Bugcrowd 404. /security 200 but is homepage shell (no disclosure content); /responsible-disclosure 404. -> L0.” | ||||||
| 77 | HUB24 hub24.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (no Wayback). HackerOne GraphQL NOT_FOUND. Bugcrowd 404. /security + /responsible-disclosure + /vulnerability-disclosure-policy all 200 but are Incapsula WAF challenge shells (byte-identical to a nonsense control) — not real pages. -> L0.” | ||||||
| 78 | Ramelius Resources rameliusresources.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404. HackerOne GraphQL NOT_FOUND (2 slugs). Bugcrowd 404. /security + /responsible-disclosure 404. Only internal info-security policy. -> L0.” | ||||||
| 79 | Bendigo and Adelaide Bank bendigoadelaide.com.au |
Bugcrowd ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: https://bugcrowd.com/engagements/bendigobank-vdp · Policy: https://www.bendigobank.com.au/security/ben-protect/responsible-disclosure/
“Open Bugcrowd VDP (in_progress, open, safeHarborStatus 'declined'). Own page → Bugcrowd; 'does not compensate'. Only legal sentence is boilerplate ('comply... with the BugCrowd Standard Disclosure Terms') — no authored safe harbor/authorization/carve-out -> L2. HackerOne bendigobank empty stub (does not count).” | ||||||
| 80 | AGL Energy agl.com.au |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: security@agl.com.au · Policy: https://www.agl.com.au/terms-conditions/responsible-disclosure-policy
“Real responsible-disclosure policy (scope + security@agl.com.au). Narrow conditional auth only: 'We allow you to conduct vulnerability research and testing only on our services... to which you have authorised access.' Anti-protective: 'AGL does not condone any malicious or illegal behaviour...'. 72h ack SLA (not deadline). No safe harbor/carve-out -> L2. HackerOne aglenergy empty stub.” | ||||||
| 81 | Steadfast Group steadfast.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt HTML 404 both paths + Wayback. HackerOne NOT_FOUND (2 slugs). Bugcrowd 404 x3. Only a privacy breach clause. -> L0.” | ||||||
| 82 | Downer EDI downergroup.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (apex+www; Wayback 404 since 2023). HackerOne NOT_FOUND (4 slugs). Bugcrowd none. Policies index (23 policies) has no security/VDP. -> L0.” | ||||||
| 83 | Cleanaway Waste Management cleanaway.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt HTML 404 both paths + Wayback. HackerOne NOT_FOUND (3 slugs). Bugcrowd 404 x3. No disclosure page. -> L0.” | ||||||
| 84 | Regis Resources regisresources.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (apex 301→www→404; no Wayback). HackerOne NOT_FOUND (3 slugs). Bugcrowd none. Only legal/privacy/governance + a 2026 ransomware writeup. -> L0.” | ||||||
| 85 | Telix Pharmaceuticals telixpharma.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne GraphQL NOT_FOUND (2 slugs). Bugcrowd 404 x2. security.txt 404 both paths. Only privacy@telixpharma.com (privacy). -> L0.” | ||||||
| 86 | Seek seek.com.au |
Bugcrowd ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: https://bugcrowd.com/engagements/seek · Policy: https://bugcrowd.com/engagements/seek
“Open public Bugcrowd bug-bounty (engagement in_progress, pay_for_success). SEEK page links it. Brief has scope+submit+rewards but NO safe harbor/non-pursuit/authorization/carve-out — in fact restrictive ('Customer instances are not to be accessed... will be considered a breach of our Terms and Conditions') -> L2. HackerOne NOT_FOUND.” | ||||||
| 87 | Westgold Resources westgold.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne GraphQL NOT_FOUND (2 slugs). Bugcrowd 404. security.txt 404 both paths. Only ESG mentions of internal controls. -> L0.” | ||||||
| 88 | Metcash metcash.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 both paths. HackerOne GraphQL NOT_FOUND. Bugcrowd 404 x2. Only privacy@metcash.com (privacy). -> L0.” | ||||||
| 89 | A2 Milk Company thea2milkcompany.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 404 (thea2milkcompany.com); US sub a2milk.com/security.txt 200 but empty HTML SPA shell (no Contact, rejected). HackerOne NOT_FOUND (3 slugs). Bugcrowd 404. -> L0.” | ||||||
| 90 | Ansell ansell.com |
Web form ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: security.vdr@ansell.com · Policy: https://www.ansell.com/us/en/legal/vulnerability-disclosure-policy
“Authored VDP. Testing auth + non-pursuit: 'we will consider your research to be authorised and... Ansell will not recommend or pursue legal action related to your research.' Third-party defense + published CVD timeline: '90 calendar days... (software) or 120 calendar days... (hardware, firmware, and wireless).' BUT only ONE carve-out (non-pursuit/anti-hacking-equiv); NO DMCA/anti-circumvention, NO ToS waiver → fails L4 '≥2 carve-outs' gate despite the timeline -> L3 (re-verified directly). Valid text/plain security.txt.” | ||||||
| 91 | AMP Limited amp.com.au |
security.txt ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: infosec@amp.com.au
“Real text/plain security.txt: ASCII banner 'infosec ... at amp.com.au' + encryption pubkey. Contact only, no policy/scope/safe harbor -> L1. HackerOne 'ampau' is a directory stub (submission_state:null). No Bugcrowd.” | ||||||
| 92 | Bank of Queensland boq.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. HackerOne 'boq' stub (GraphQL submission_state:null); bankofqueensland not found. security.txt 404 both paths (boq.com.au + boqgroup.com). Bugcrowd 404. /responsible-disclosure real 404. Own pages = customer fraud guidance only. -> L0.” | ||||||
| 93 | Dyno Nobel dynonobel.com.au |
security.txt ↗ | — | L1 | 2026-06-21 | ▸ |
Contact Only deep audit · confidence high
Report via: itsecurity@Incitech.com.au
“Real text/plain security.txt (also on dynonobel.com + parent incitecpivot.com.au): 'Contact: mailto:itsecurity@Incitech.com.au / Expires 2025-12-31'. Contact only, no policy -> L1. CAVEAT: EXPIRED (2025-12-31) and contact host Incitech.com.au is NXDOMAIN — email currently unreachable, but a valid Contact line is served live. No HackerOne/Bugcrowd.” | ||||||
| 94 | Fisher & Paykel Healthcare fphcare.com |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: securityreports@fphcare.com · Policy: https://www.fphcare.com/us/corporate/contact-us/product-security/report-a-vulnerability/
“Own coordinated-disclosure policy: 'we support coordinated vulnerability disclosure... We welcome vulnerability testing... please send an email to securityreports@fphcare.com.' 10-business-day response SLA (not a deadline). NO safe harbor/non-pursuit, NO statutory carve-out, NO deadline. 'Welcome testing' is encouragement, not authorization-with-carve-outs -> L2. No security.txt, no platform program.” | ||||||
| 95 | Light & Wonder lnw.com |
Email ↗ | policy ↗ | L2 | 2026-06-21 | ▸ |
Basic VDP deep audit · confidence high
Report via: securityreporting@lnw.com · Policy: https://explore.lnw.com/responsible-reporting/
“Own 'Responsible Reporting' policy: scope + 'report it as soon as possible to securityreporting@lnw.com.' NO safe harbor/non-pursuit; RESTRICTS the researcher ('Please DO NOT... Take any action that might violate any applicable laws or agreements'), no testing authorization, no carve-out, no deadline -> L2. No security.txt, no platform program.” | ||||||
| 96 | ResMed resmed.com |
HackerOne ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://hackerone.com/resmed · Policy: https://hackerone.com/resmed
“Real OPEN HackerOne program (GraphQL submission_state:'open', state:'public_mode') with authored Safe Harbor: 'Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you...'. Promissory non-pursuit + authorization, but NO named statutory carve-outs (no CFAA/DMCA/ToS; <2 for L4), resolution case-by-case (no deadline) -> L3. Own resmed.com/security + ap.resmed.com link to it; no security.txt.” | ||||||
| 97 | Sandfire Resources sandfire.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt 301→www→404 both paths. HackerOne GraphQL NOT_FOUND (2 slugs). Bugcrowd 404 x2. Only general + Ethics Line (conduct, not security). -> L0.” | ||||||
| 98 | Sigma Healthcare sigmahealthcare.com.au |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt clean 404 both paths. HackerOne GraphQL NOT_FOUND (2 slugs). Bugcrowd 404 x2. Only Privacy Officer email. All 'Sigma' VDP hits were DIFFERENT companies (Sigma360/Computing/Aldrich). -> L0.” | ||||||
| 99 | Treasury Wine Estates tweglobal.com |
— | — | L0 | 2026-06-21 | ▸ |
Not Present deep audit · confidence high
“No channel. security.txt FAKE-200: serves Next.js HTML SPA shell (not text/plain, no Contact:) — HTML-masquerade trap. HackerOne no team. Bugcrowd none. Only general/investor contacts. -> L0.” | ||||||
| 100 | Block Inc block.xyz |
Bugcrowd ↗ | policy ↗ | L3 | 2026-06-21 | ▸ |
Partial Safe Harbor deep audit · confidence high
Report via: https://bugcrowd.com/engagements/cashapp · Policy: https://bugcrowd.com/engagements/cashapp
“Real public Cash App / Block Bugcrowd bounty (since Jun 2020; P1 $5k-$18k; 53 vulns). Authored policy: 'we promise not to bring legal action against researchers who: Share with us the full details... Do not disclose the issue to others until we've had a reasonable time to address it and disclosure has been approved by us.' Non-pursuit + authorized testing, but ZERO CFAA/DMCA/ToS carve-outs in authored prose (keyword-searched), and disclosure is gated (no CVD timeline) → fails two-of-three L4 → L3. cash.app security.txt valid (text/plain → Bugcrowd). block.xyz itself no security.txt. (Block migrated off HackerOne — square NOT_FOUND.)” | ||||||