Electricity North West · Vulnerability Disclosure

Electricity North West Vulnerability Disclosure

Vulnerability disclosure

A vulnerability-reporting route exists for this API, but it belongs to the platform vendor rather than to the network operator. The Opendatasoft (Huwise) tenant that serves the SP Electricity North West open data API publishes an RFC 9116 security.txt at the API host root, and the vendor's security page names a security team address and describes an incident-handling process. Electricity North West itself publishes nothing reachable: www.enwl.co.uk sits behind a Cloudflare managed challenge that returns HTTP 403 to every non-browser client, so its /.well-known/security.txt could not be retrieved or ruled out.

Electricity North West runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyUnited KingdomUtilitiesElectricityGridDistribution NetworkOpen DataDERRenewablesEnergy MarketsSmart Metering
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@opendatasoft.com
Contact
mailto:security@huwise.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
description: >-
  A vulnerability-reporting route exists for this API, but it belongs to the
  platform vendor rather than to the network operator. The Opendatasoft (Huwise)
  tenant that serves the SP Electricity North West open data API publishes an
  RFC 9116 security.txt at the API host root, and the vendor's security page names
  a security team address and describes an incident-handling process. Electricity
  North West itself publishes nothing reachable: www.enwl.co.uk sits behind a
  Cloudflare managed challenge that returns HTTP 403 to every non-browser client,
  so its /.well-known/security.txt could not be retrieved or ruled out.
policy:
- https://www.huwise.com/en/security/
contact:
- mailto:security@opendatasoft.com
- mailto:security@huwise.com
security_txt:
  url: https://electricitynorthwest.opendatasoft.com/.well-known/security.txt
  status: 200
  rfc: RFC 9116
  file: well-known/electricity-north-west-security.txt
  fields:
    Contact: mailto:security@opendatasoft.com
    Expires: '2050-01-01T11:00:00.000Z'
    Preferred-Languages: en,fr
  gaps:
  - >-
    No "Policy:" field — the file points at a mailbox, not a written disclosure
    policy.
  - 'No "Encryption:", "Acknowledgments:" or "Hiring:" fields.'
  - >-
    Expires is set to 2050-01-01, far beyond the RFC 9116 recommendation of no
    more than a year out.
bug_bounty:
  program: null
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  found: false
disclosure_program:
  documented: true
  url: https://www.huwise.com/en/security/
  operated_by: Opendatasoft SAS (Huwise) — platform vendor
  quotes:
  - >-
    "If you wish to report a security vulnerability, you can contact Huwise's
    security team at security@huwise.com."
  - >-
    "In case of a security incident, Huwise has put in place a process and
    organizational structure to deal with security incidents as quickly as
    possible."
  related_practices:
  - Regular third-party penetration testing programme.
  - Daily security inspection of servers and software for known vulnerabilities.
  - Major-impact vulnerabilities patched "usually within one day".
  - Passwords stored hashed with PBKDF2.
  security_policy_basis: >-
    The vendor states its information-security policy "is based on the ISO 27001
    and ISO 27002 standards". That is a statement of basis, NOT a certification
    claim — no certificate, audit report, SOC 2, PCI, HIPAA or FedRAMP attestation
    is named anywhere on the page. Recorded as such; no Compliance pointer is
    emitted for it.
provider_own_surface:
  domain: enwl.co.uk
  security_txt_status: 403
  note: >-
    Cloudflare managed challenge blocks all non-browser requests to www.enwl.co.uk,
    including /.well-known/security.txt, /robots.txt and /favicon.ico. This is an
    inability to observe, not a confirmed absence.
  data_portal_contact: dataportal@enwl.co.uk
evidence:
- source: https://electricitynorthwest.opendatasoft.com/.well-known/security.txt
  kind: security.txt
  status: 200
  date: '2026-07-27'
- source: https://www.huwise.com/en/security/
  kind: security page
  status: 200
  date: '2026-07-27'
  keywords: [security@huwise.com, vulnerability, penetration testing, security incident, ISO 27001]
- source: https://www.enwl.co.uk/.well-known/security.txt
  kind: security.txt
  status: 403
  date: '2026-07-27'