Eon Next Vulnerability Disclosure
E.ON Next's vulnerability-reporting channel is the E.ON group one, published as a PGP-signed RFC 9116 security.txt and served identically from www.eonnext.com, eonnext.com and the parent site www.eon.com. It is a contact, not a programme: the file carries Contact, Expires, Encryption and Preferred-Languages, and no Policy, Acknowledgments or CSAF field. No bug bounty (HackerOne, Bugcrowd, Intigriti) was found under E.ON, E.ON Next or eonnext.com, and the group's own security pages on www.eon.com answer HTTP 403 to every machine client, so no safe-harbour terms could be read.
E.ON Next runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.