Smart DCC · Vulnerability Disclosure

Dcc Smart Vulnerability Disclosure

Vulnerability disclosure

Smart DCC runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

EnergyUnited KingdomUtilitiesElectricityGasSmart MeteringGridMetering InfrastructureEnergy Data
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
informationsecurity@smartdcc.co.uk

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://www.smartdcc.co.uk/media/sn5dn4hr/information-security-policy-3.pdf
summary: >-
  Smart DCC publishes no RFC 9116 security.txt, no responsible-disclosure page and no bug
  bounty programme (HackerOne, Bugcrowd and Intigriti were all checked and none was found).
  What it does publish is a board-level Information Security Policy, linked from the footer
  of every page, which names a Chief Information Security Officer as the accountable owner
  and gives a monitored security mailbox. That mailbox is the only published route for
  reporting a security concern.
policy:
- https://www.smartdcc.co.uk/media/sn5dn4hr/information-security-policy-3.pdf
contact:
- informationsecurity@smartdcc.co.uk
security_txt: false
bug_bounty: null
programs_checked:
- {program: HackerOne, found: false}
- {program: Bugcrowd, found: false}
- {program: Intigriti, found: false}
- {path: /.well-known/security.txt, status: 404}
- {path: /security, status: 404}
- {path: /responsible-disclosure, status: 404}
evidence:
- source: https://www.smartdcc.co.uk/media/sn5dn4hr/information-security-policy-3.pdf
  kind: information-security-policy
  detail: >-
    Information Security Policy v5.4, next review November 2026. Sets out the DCC Board's
    accountability for information security, a RACI with the CISO accountable and the
    Security Function responsible, a Security Architecture Framework aligned to the NIST
    Cybersecurity Framework 2.0 and mapped to ISO/IEC 27001:2022, and an ISMS described in
    the DCC ISMS Manual. Policy exceptions are raised to informationsecurity@smartdcc.co.uk.
- source: https://www.smartdcc.co.uk/major-incident-management/
  kind: incident-transparency
  detail: >-
    Public monthly publication of all Category 1 incidents with a published definition and
    a stated 24/7 monitoring capability.
gaps:
- No /.well-known/security.txt (RFC 9116)
- No published coordinated vulnerability disclosure policy or safe-harbour statement
- No bug bounty or VDP platform listing

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dcc-smart-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.