generated: '2026-07-25' method: probed probe: true result: none policy: [] contact: [] bug_bounty: present: false platforms_checked: - HackerOne - Bugcrowd - Intigriti finding: >- No coordinated vulnerability disclosure policy, security contact or bug bounty programme is published on any anonymously reachable Bharti Airtel host. This is a verified negative from 0-working/probe-security-programs.py plus additional manual probing, not an unchecked gap. evidence: - source: https://www.airtel.in/.well-known/security.txt status: 404 kind: security.txt - source: https://openapi.airtel.in/.well-known/security.txt status: 404 kind: security.txt - source: https://m2m.airteliot.co.in/.well-known/security.txt status: 404 kind: security.txt - source: https://www.airtel.in/security.txt status: 200 kind: soft-404 note: >- Returns text/html, 9,787 bytes — the airtel.in Angular SPA shell with the consumer homepage title. Not an RFC 9116 document. - source: https://www.airtel.in/responsible-disclosure status: 200 kind: soft-404 note: 8,991-byte SPA shell, byte-identical to /security, /vulnerability-disclosure and /about-bharti/security. - source: https://www.airtel.in/security status: 200 kind: soft-404 - source: https://www.airtel.in/vulnerability-disclosure status: 200 kind: soft-404 - source: https://www.airtel.in/about-bharti/security status: 200 kind: soft-404 note: >- No `Security` pointer is emitted in apis.yml for this provider — there is no disclosure page or security policy to point at. Airtel does publish product-side API security (the Airtel WAAP offering at https://www.airtel.in/b2b/waap is a Web Application and API Protection product it SELLS), which is not the same thing as a disclosure programme for its own APIs and is not recorded as one.