generated: '2026-07-27' method: searched probe: true description: >- AGL runs a named Responsible Disclosure Program with a published policy page. It is a coordinated-disclosure programme, explicitly NOT a bug bounty — AGL states it is unable to offer any form of compensation, monetary or otherwise, for a disclosure, and requires research to be conducted only against services and products the researcher has authorised access to. The policy page could not be read by any machine client (the Akamai edge in front of www.agl.com.au returns HTTP 403 to every non-browser request, including WebFetch and curl with a browser User-Agent), so its existence and substance were established from the public search index rather than from a direct fetch. Recorded honestly with the observed HTTP status. policy: - https://www.agl.com.au/terms-conditions/responsible-disclosure-policy contact: [] contact_note: >- No security contact address is published in a machine-readable form. There is no /.well-known/security.txt on any AGL host (all probes 404 or 403 — see well-known/agl-energy-well-known.yml), and the reporting channel named on the policy page could not be read through the edge block. bug_bounty: false bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti programme was found for AGL. The policy page states AGL is unable to offer compensation for disclosures. safe_harbour: stated: partial detail: >- The policy requires research to be responsible, lawful, and limited to services and products the researcher has authorised access to, and states that AGL does not condone malicious or illegal behaviour in identifying or reporting vulnerabilities. evidence: - source: https://www.agl.com.au/terms-conditions/responsible-disclosure-policy kind: responsible-disclosure-policy http_status: 403 http_status_note: Akamai edge denies non-browser clients; 403 is an access block, not an absence. verified_via: public search index result confirming the page title "Responsible Disclosure Policy" and its terms date: '2026-07-27' - source: https://www.agl.com.au/.well-known/security.txt kind: security.txt http_status: 403 - source: https://public.cdr.agl.com.au/.well-known/security.txt kind: security.txt http_status: 404 probes_run: script: 0-working/probe-security-programs.py result: 'vdp=none trust=none' result_note: >- The mechanical probe found nothing because every AGL corporate URL answers 403 to it. The policy was recovered by search instead. This artifact supersedes the probe result.