generated: '2026-07-25' method: searched probe: true source: https://www.teliacompany.com/assets/u5c1v3pt22v8/3hKQp1pJJJZ4EpquWVZ9rk/17d86f87acc6cf544b38f1a70ce2f069/Supplier_Security_Directive_8.0_2024-09-11.pdf notes: >- Telia Company publishes a vulnerability reporting channel, but not where a developer would look for one. There is no /.well-known/security.txt on any Telia host and no responsible-disclosure page on the corporate site. The verified contact is published inside the public Supplier Security Directive (v8.0, 2024-09-11), which instructs reporters to notify cert@teliacompany.com about zero-day and other material vulnerabilities within 24 hours of identification, and controlcenterem-security@teliacompany.com for personal-data breaches. A HackerOne handle for TeliaSonera AB also resolves (HTTP 200), but its policy content could not be read anonymously, so it is recorded as unverified rather than claimed. CORRECTION - an automated probe of https://www.teliacompany.com/security/responsible-disclosure initially scored a hit; that URL is a SOFT 404. www.teliacompany.com returns HTTP 200 with a slug-derived title and description for any path (verified against a nonsense URL), so the "responsible disclosure" keyword match came from the auto-generated title, not from a real policy page. That false positive has been removed. contact: - cert@teliacompany.com - controlcenterem-security@teliacompany.com policy: [] security_txt: false bug_bounty: program: null verified: false candidate: https://hackerone.com/teliasoneraab candidate_note: resolves HTTP 200 as "TeliaSonera | Vulnerability Disclosure Policy"; program scope and status could not be read without a HackerOne session, so no claim is made about whether it is live or in scope for the API estate disclosure_window: >- Suppliers must inform Telia at cert@teliacompany.com about any zero-day or other vulnerability with material impact on a deliverable as soon as possible and no later than 24 hours after identification. evidence: - source: https://www.teliacompany.com/assets/u5c1v3pt22v8/3hKQp1pJJJZ4EpquWVZ9rk/17d86f87acc6cf544b38f1a70ce2f069/Supplier_Security_Directive_8.0_2024-09-11.pdf kind: published security directive (PDF, first-party, public) quote: The Supplier shall inform the Buyer at cert@teliacompany.com about any zero-day vulnerabilities and other vulnerabilities which may have a material impact on the Deliverable as soon as possible but no later than 24 hours. http_status: 200 - source: https://www.teliacompany.com/en/solutions/global/security-advisory kind: security advisory page (JavaScript application, content not readable anonymously) http_status: 200 probed_and_absent: - /.well-known/security.txt on tunnistus.telia.fi (404) - /.well-known/security.txt on api-garden.teliacompany.com (404) - /.well-known/security.txt on lso / camara / developer.telia.fi / api.messaging (SPA soft 200, not a document) - https://www.teliacompany.com/security/responsible-disclosure (soft 404)