Centrica Vulnerability Disclosure
British Gas operates a published responsible-disclosure policy, advertised from an RFC 9116 security.txt on the retail supply host. This is the only coordinated-disclosure surface found anywhere in the Centrica group: www.centrica.com serves no security.txt (404) and blocks /security with a WAF 403, and the FieldOps partner platform hosts serve nothing under /.well-known/. There is no bug bounty programme — no HackerOne, Bugcrowd, Intigriti or YesWeHack listing was found for Centrica, British Gas, Bord Gais Energy or Hive — and the security.txt itself omits the RFC 9116 REQUIRED Contact and Expires fields, so it is disclosure signposting rather than a conformant machine-readable record.
Centrica runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.