Centrica Vulnerability Disclosure
British Gas operates a published responsible-disclosure policy, advertised from an RFC 9116 security.txt on the retail supply host. This is the only coordinated-disclosure surface found anywhere in the Centrica group: www.centrica.com serves no security.txt (404) and blocks /security with a WAF 403, and the FieldOps partner platform hosts serve nothing under /.well-known/. There is no bug bounty programme — no HackerOne, Bugcrowd, Intigriti or YesWeHack listing was found for Centrica, British Gas, Bord Gais Energy or Hive — and the security.txt itself omits the RFC 9116 REQUIRED Contact and Expires fields, so it is disclosure signposting rather than a conformant machine-readable record.
Centrica runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.