Centrica · Vulnerability Disclosure

Centrica Vulnerability Disclosure

Vulnerability disclosure

British Gas operates a published responsible-disclosure policy, advertised from an RFC 9116 security.txt on the retail supply host. This is the only coordinated-disclosure surface found anywhere in the Centrica group: www.centrica.com serves no security.txt (404) and blocks /security with a WAF 403, and the FieldOps partner platform hosts serve nothing under /.well-known/. There is no bug bounty programme — no HackerOne, Bugcrowd, Intigriti or YesWeHack listing was found for Centrica, British Gas, Bord Gais Energy or Hive — and the security.txt itself omits the RFC 9116 REQUIRED Contact and Expires fields, so it is disclosure signposting rather than a conformant machine-readable record.

Centrica runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

EnergyUnited KingdomUtilitiesElectricityGasSmart MeteringEnergy RetailEnergy MarketsIrelandField Service
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://www.britishgas.co.uk/.well-known/security.txt
description: >-
  British Gas operates a published responsible-disclosure policy, advertised from an
  RFC 9116 security.txt on the retail supply host. This is the only coordinated-disclosure
  surface found anywhere in the Centrica group: www.centrica.com serves no security.txt
  (404) and blocks /security with a WAF 403, and the FieldOps partner platform hosts serve
  nothing under /.well-known/. There is no bug bounty programme — no HackerOne, Bugcrowd,
  Intigriti or YesWeHack listing was found for Centrica, British Gas, Bord Gais Energy or
  Hive — and the security.txt itself omits the RFC 9116 REQUIRED Contact and Expires fields,
  so it is disclosure signposting rather than a conformant machine-readable record.
policy:
- https://www.britishgas.co.uk/global-maintenance/responsible-disclosure.html
contact: []
bug_bounty: false
bug_bounty_platform: null
safe_harbor: not stated
disclosure_form: >-
  Reports are submitted through a web form on the responsible-disclosure page; no email
  address, PGP key or Contact: URI is published.
policy_terms:
  acknowledgement: British Gas states it will acknowledge the submission and review the reported issue.
  remediation_estimate: An estimate of remediation time is given once an issue is confirmed.
  public_disclosure: Researchers are asked not to make vulnerability information public.
  out_of_scope:
  - Accessible non-sensitive files and directories (README.txt, robots.txt)
  - Fingerprinting / banner / version disclosure of common public services
  - Username or email enumeration by brute force or error-message inference
  prohibited:
  - Public disclosure of personal, proprietary or financial information
  - Modification or deletion of data that is not the researcher's own
  - Interruption, degradation or outage of services (denial of service)
  - Spamming, social engineering and phishing
  - Physical exploits or attacks on infrastructure
  - Local network attacks such as DNS poisoning or ARP spoofing
evidence:
- source: well-known/centrica-security.txt
  kind: security.txt
  status: 200
  note: Redirects to https://www.britishgas.co.uk/global-maintenance/security.txt, text/plain.
- source: https://www.britishgas.co.uk/global-maintenance/responsible-disclosure.html
  kind: disclosure-policy-page
  status: 200
  note: Full responsible-disclosure policy with scope, prohibited activity and handling commitments.
probes:
- url: https://www.centrica.com/.well-known/security.txt
  status: 404
- url: https://www.centrica.com/security
  status: 403
  note: Corporate WAF blocks the path anonymously.
- url: https://api-developer.dev.fieldops.centrica.com/.well-known/security.txt
  status: 404
- url: https://api.dev.fieldops.centrica.com/.well-known/security.txt
  status: 404
- url: https://centricaenergy.com/.well-known/security.txt
  status: 404
- url: https://trust.centrica.com/
  status: 000
  note: DNS does not resolve.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/centrica-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.