generated: '2026-09-06' method: searched source: >- the "Vulnerability Disclosure Policy" link in the bpa.gov site footer, followed to https://www.energy.gov/cio/articles/vulnerability-disclosure-policy provider: Bonneville Power Administration providerId: bonneville-power-administration description: >- BPA does publish a route to report a vulnerability, but not one of its own and not at the machine-readable address. Every page of bpa.gov carries a footer link labelled "Vulnerability Disclosure Policy" pointing at the Department of Energy's VDP — BPA is a DOE power marketing administration, so DOE's policy is the governing one. There is no security.txt on any BPA host. program: published: true scope: department-level first_party: false policy_url: https://www.energy.gov/cio/articles/vulnerability-disclosure-policy policy_owner: U.S. Department of Energy, Office of the Chief Information Officer linked_from: https://www.bpa.gov/ (site footer, present on every page) bug_bounty: false paid: false safe_harbor: stated in the DOE policy reporting_channels: - type: portal url: https://doe.responsibledisclosure.com http_status: 403 note: >- The DOE policy names this as the primary submission portal. It returned 403 to our client on 2026-09-06 — an edge/bot policy, not evidence the portal is gone; recorded with the status observed rather than judged dead. - type: email value: DOEOCIOInfo@hq.doe.gov source: stated in the DOE vulnerability disclosure policy - type: phone value: (202) 586-0166 source: stated in the DOE vulnerability disclosure policy scope_caveat: >- The DOE policy uses a progressive scope model — at issuance at least one DOE public internet-accessible system is in scope, expanding on a schedule until all DOE-produced public-facing systems are covered. It names no agency and does not mention BPA or bpa.gov explicitly. A reporter therefore cannot confirm from the policy text alone that a given BPA system is in scope; BPA's own footer link is the assertion that it applies. gaps: - id: no-security-txt detail: >- No /.well-known/security.txt on bpa.gov, www.bpa.gov, transmission.bpa.gov or data-bpagis.hub.arcgis.com. An RFC 9116 file pointing at the DOE policy and contact would cost BPA nothing and make the route machine-discoverable. evidence: - url: https://www.bpa.gov/.well-known/security.txt http_status: 404 - url: https://bpa.gov/.well-known/security.txt http_status: 404 - url: https://transmission.bpa.gov/.well-known/security.txt http_status: 200 note: HTML site shell, not RFC 9116 text — the host answers 200 for every /.well-known/ path. - url: https://data-bpagis.hub.arcgis.com/.well-known/security.txt http_status: 404 - id: no-bpa-specific-policy detail: >- No BPA-authored disclosure policy, scope statement or acknowledgements page. Reports about BPA systems go to a department-wide channel. - id: no-bug-bounty detail: >- No HackerOne, Bugcrowd or Intigriti program was found for BPA or for DOE. Searched 2026-09-06.