Centrica · Vulnerability Disclosure

Centrica Vulnerability Disclosure

Vulnerability disclosure

British Gas operates a published responsible-disclosure policy, advertised from an RFC 9116 security.txt on the retail supply host. This is the only coordinated-disclosure surface found anywhere in the Centrica group: www.centrica.com serves no security.txt (404) and blocks /security with a WAF 403, and the FieldOps partner platform hosts serve nothing under /.well-known/. There is no bug bounty programme — no HackerOne, Bugcrowd, Intigriti or YesWeHack listing was found for Centrica, British Gas, Bord Gais Energy or Hive — and the security.txt itself omits the RFC 9116 REQUIRED Contact and Expires fields, so it is disclosure signposting rather than a conformant machine-readable record.

Centrica runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

EnergyUnited KingdomUtilitiesElectricityGasSmart MeteringEnergy RetailEnergy MarketsIrelandField Service
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://www.britishgas.co.uk/.well-known/security.txt
description: >-
  British Gas operates a published responsible-disclosure policy, advertised from an
  RFC 9116 security.txt on the retail supply host. This is the only coordinated-disclosure
  surface found anywhere in the Centrica group: www.centrica.com serves no security.txt
  (404) and blocks /security with a WAF 403, and the FieldOps partner platform hosts serve
  nothing under /.well-known/. There is no bug bounty programme — no HackerOne, Bugcrowd,
  Intigriti or YesWeHack listing was found for Centrica, British Gas, Bord Gais Energy or
  Hive — and the security.txt itself omits the RFC 9116 REQUIRED Contact and Expires fields,
  so it is disclosure signposting rather than a conformant machine-readable record.
policy:
- https://www.britishgas.co.uk/global-maintenance/responsible-disclosure.html
contact: []
bug_bounty: false
bug_bounty_platform: null
safe_harbor: not stated
disclosure_form: >-
  Reports are submitted through a web form on the responsible-disclosure page; no email
  address, PGP key or Contact: URI is published.
policy_terms:
  acknowledgement: British Gas states it will acknowledge the submission and review the reported issue.
  remediation_estimate: An estimate of remediation time is given once an issue is confirmed.
  public_disclosure: Researchers are asked not to make vulnerability information public.
  out_of_scope:
  - Accessible non-sensitive files and directories (README.txt, robots.txt)
  - Fingerprinting / banner / version disclosure of common public services
  - Username or email enumeration by brute force or error-message inference
  prohibited:
  - Public disclosure of personal, proprietary or financial information
  - Modification or deletion of data that is not the researcher's own
  - Interruption, degradation or outage of services (denial of service)
  - Spamming, social engineering and phishing
  - Physical exploits or attacks on infrastructure
  - Local network attacks such as DNS poisoning or ARP spoofing
evidence:
- source: well-known/centrica-security.txt
  kind: security.txt
  status: 200
  note: Redirects to https://www.britishgas.co.uk/global-maintenance/security.txt, text/plain.
- source: https://www.britishgas.co.uk/global-maintenance/responsible-disclosure.html
  kind: disclosure-policy-page
  status: 200
  note: Full responsible-disclosure policy with scope, prohibited activity and handling commitments.
probes:
- url: https://www.centrica.com/.well-known/security.txt
  status: 404
- url: https://www.centrica.com/security
  status: 403
  note: Corporate WAF blocks the path anonymously.
- url: https://api-developer.dev.fieldops.centrica.com/.well-known/security.txt
  status: 404
- url: https://api.dev.fieldops.centrica.com/.well-known/security.txt
  status: 404
- url: https://centricaenergy.com/.well-known/security.txt
  status: 404
- url: https://trust.centrica.com/
  status: 000
  note: DNS does not resolve.