generated: '2026-07-31' method: searched probe: true program: name: Responsible Vulnerability Disclosure Program (RVDP) operator: Ather Energy Limited self_hosted: true platform: null note: >- Ather runs its own program directly — no HackerOne, Bugcrowd or Intigriti listing was found. Reports are submitted by email to the Ather security team with the subject line "Bug Bounty", or through the dedicated contact form. The program is open to individuals only, not organisations. policy: - https://www.atherenergy.com/bug-bounty - https://www.atherenergy.com/bug-bounty-terms contact: - https://www.atherenergy.com/contact/bug-bounty rewards: true safe_harbor_documented: true requirements: - Adherence to Ather's Responsible Disclosure & Reporting Guidelines is mandatory. - Do not run tests that may disrupt Ather applications or services. - Demonstrate impact in a secure manner that protects sensitive data and user privacy. - On discovering exposure of non-public or personally identifiable information, stop testing and notify Ather immediately. - Purge any stored non-public or PII data upon reporting a vulnerability. - Open to individuals only, not to organisations. security_txt: present: false probed: https://www.atherenergy.com/.well-known/security.txt status: 404 gap: >- Ather publishes a real disclosure program but does not advertise it at the RFC 9116 /.well-known/security.txt location, so automated discovery misses it. evidence: - source: https://www.atherenergy.com/sitemap.xml kind: provider-sitemap note: /bug-bounty, /bug-bounty-terms and /contact/bug-bounty are all listed in Ather's own sitemap - source: https://www.atherenergy.com/bug-bounty kind: disclosure-page title: Responsible Vulnerability Disclosure Program | Ather Energy - source: https://www.atherenergy.com/bug-bounty-terms kind: program-terms title: Bug Bounty Terms And Conditions | Ather Energy - source: https://www.atherenergy.com/contact/bug-bounty kind: report-intake title: Contact Us | Ather Energy in Bug Bounty http_status: 200 x-evidence: fetched: '2026-07-31' http_status: 403 note: >- Ather's HTML pages sit behind Cloudflare bot protection and return 403 to non-browser clients (verified with browser-equivalent headers), so page bodies could not be captured verbatim. Existence and titles are confirmed from Ather's own published sitemap.xml (HTTP 200) plus indexed page titles; /contact/bug-bounty returns HTTP 200 to a plain HEAD. Nothing here is inferred beyond what Ather itself publishes.