generated: '2026-07-25' method: searched probe: true source: https://bugcrowd.com/engagements/bupa-aus-vdp-pro program: name: Bupa Australia Vulnerability Disclosure Engagement type: vulnerability-disclosure platform: Bugcrowd url: https://bugcrowd.com/engagements/bupa-aus-vdp-pro http_status: 200 managed_by: Bupa Australia Pty Limited bounty: false note: >- Bugcrowd classifies the engagement as "Vulnerability Disclosure", not a paid bug bounty. The public engagement page renders its brief (scope, safe-harbour text, submission form) client-side behind the Bugcrowd researcher experience, so the scope list and reward table could not be read anonymously and are deliberately not reproduced here. policy: - https://bugcrowd.com/engagements/bupa-aus-vdp-pro contact: [] security_txt: published: false note: >- No RFC 9116 security.txt is served on any Bupa host. /.well-known/ security.txt returns 404 on www.bupa.com, bupa.com, portal.api.bupa.com.au, www.bupa.com.au, www.bupa.co.uk and bupaglobal.com; 502 on api.bupa.com.au; and an HTML SPA shell / block page (not a text/plain policy) on apidoc.bupa.cl and api.bupa.cl. See well-known/bupa-well-known.yml. evidence: - source: https://bugcrowd.com/engagements/bupa-aus-vdp-pro kind: bug-bounty-platform-page fetched: '2026-07-25' http_status: 200 detail: >- Page title "Vulnerability Disclosure: Bupa Australia Vulnerability Disclosure Engagement - Bugcrowd". - source: https://www.bupa.com/impact/responsible-business/business-ethics/managing-cybersecurity-risks kind: corporate-security-governance-page fetched: '2026-07-25' http_status: 200 detail: >- Group-level cybersecurity page. Describes a "Bupa-wide Enterprise Policy on Information Security and related Standards", a three-lines-of-defence risk model, oversight by the Bupa Enterprise Risk Committee and Board Risk Committee, and "accredited cybersecurity experts for independent assessments". It names no certification and does not reference a vulnerability disclosure programme or a security contact address. not_found: - what: HackerOne programme detail: >- https://hackerone.com/bupa returns HTTP 200 but serves the generic HackerOne single-page shell (title "HackerOne") with no Bupa programme payload; no HackerOne programme for Bupa could be confirmed. - what: group-level responsible disclosure page detail: >- /security, /responsible-disclosure and /vulnerability-disclosure all return 404 on www.bupa.com; on www.bupa.com.au they return HTTP 200 soft-404s (page title "404", canonical https://www.bupa.com.au/404); www.bupa.co.uk returns 403 to automated clients.