generated: '2026-07-25' method: searched probe: true description: >- TELUS publishes a security-issue reporting page and has a program registered on HackerOne, but neither is machine-readable and neither is fully verifiable anonymously: www.telus.com returns HTTP 403 to every automated client behind Cloudflare, and the HackerOne program's policy is not public. Recorded with the exact confidence the evidence supports — no security.txt, no published bug-bounty terms, no PGP key, no disclosure SLA. policy: - https://www.telus.com/en/about/security/report-a-problem contact: [] contact_note: >- The reporting page instructs the reporter to email details of a cyber-security problem with a TELUS product or service; the address itself could not be read anonymously (Cloudflare 403) and is therefore deliberately not recorded rather than guessed. security_txt: false bug_bounty: platform: HackerOne handle: telus_old url: https://hackerone.com/telus_old public_policy: false state: unknown note: >- The HackerOne GraphQL API confirms a team with handle "telus_old" and name "TELUS_old" exists (https://hackerone.com/telus_old returns HTTP 200), but state, submission_state, policy and offers_bounties are all null to anonymous callers — the program is private or archived. There is no hackerone.com/telus (404), and no Bugcrowd or Intigriti program was found. evidence: - source: https://www.telus.com/en/about/security/report-a-problem kind: disclosure-page title: 'Report a problem regarding fraud and spam - Security | TELUS' http_status: 403 status_note: Cloudflare bot challenge for automated clients; page existence and purpose confirmed via search index. - source: https://www.telus.com/en/about/security/telus-commitment-to-security kind: security-policy-page http_status: 403 status_note: Same Cloudflare gate. - source: https://hackerone.com/telus_old kind: bug-bounty-platform http_status: 200 status_note: Program exists; policy fields null to anonymous callers. - source: https://help.inputhealth.com/.well-known/security.txt kind: security.txt http_status: 200 status_note: >- Valid RFC 9116 file, but it is Intercom's (the CHR help-centre vendor) — Contact https://bugcrowd.com/intercom and mailto:security@intercom.com, Canonical https://app.intercom.com/.well-known/security.txt. Not a TELUS disclosure channel. probes_negative: - {url: 'https://www.telus.com/.well-known/security.txt', status: 403} - {url: 'https://telus.com/.well-known/security.txt', status: 403} - {url: 'https://api.telus.com/.well-known/security.txt', status: 503} - {url: 'https://support.api.telus.com/.well-known/security.txt', status: 404} - {url: 'https://location-api.insights.telus.com/.well-known/security.txt', status: 404} - {url: 'https://docs.insights.telus.com/.well-known/security.txt', status: 404} - {url: 'https://security.telus.com/', status: DNS NXDOMAIN} confidence: medium confidence_note: >- A first-party security reporting page and a HackerOne program both exist; the machine-readable layer (security.txt, published policy, named contact, disclosure SLA) does not.