generated: '2026-07-27' method: searched probe: true source: https://donnees.hydroquebec.com/.well-known/security.txt (HTTP 200, fetched 2026-07-27) note: >- The mechanical probe pass found nothing because it checked hydroquebec.com, which answers every unknown path with an HTTP 200 soft-404 HTML page. Probing the API host directly did return a real RFC 9116 document. Important caveat: that security.txt is served by Opendatasoft, the platform vendor hosting donnees.hydroquebec.com, and names an Opendatasoft security contact — it is the disclosure route for the platform serving the API, not a Hydro-Québec-authored programme. Hydro-Québec itself publishes no security.txt, no bug bounty and no responsible-disclosure page. policy: [] contact: - mailto:security@opendatasoft.com security_txt: url: https://donnees.hydroquebec.com/.well-known/security.txt status: 200 file: well-known/hydro-quebec-security.txt rfc: RFC 9116 fields: Contact: mailto:security@opendatasoft.com Expires: '2050-01-01T11:00:00.000Z' Preferred-Languages: en,fr authored_by: opendatasoft (platform vendor) expires_note: >- An Expires value of 2050-01-01 far exceeds the RFC 9116 recommendation that the value be less than a year in the future. bug_bounty: program: null platform: null note: No HackerOne, Bugcrowd or Intigriti programme found for Hydro-Québec. disclosure_pages_probed: - {url: 'https://www.hydroquebec.com/.well-known/security.txt', status: 200, present: false, note: soft-404 HTML} - {url: 'https://www.hydroquebec.com/security/', status: 200, present: false, note: soft-404 HTML} - {url: 'https://www.hydroquebec.com/responsible-disclosure/', status: 200, present: false, note: soft-404 HTML} - {url: 'https://donnees.hydroquebec.com/.well-known/security.txt', status: 200, present: true} alternate_contact: name: Hydro-Québec Open Data team url: https://www.hydroquebec.com/sefco2016/en/open-data-contact-us.html status: 200 verified: '2026-07-27' note: >- A general contact form for the open data programme, not a security channel. Recorded because it is the only Hydro-Québec-operated route to the people who run this API. evidence: - {source: 'https://donnees.hydroquebec.com/.well-known/security.txt', kind: security.txt, status: 200} - {source: well-known/hydro-quebec-security.txt, kind: saved verbatim} gaps: - Hydro-Québec publishes no vulnerability disclosure policy of its own. - No security.txt on the corporate domain. - No named coordinated-disclosure timeline, safe-harbour statement or PGP key.