Ordnance Survey · Vulnerability Disclosure
Ordnance Survey Vulnerability Disclosure
Vulnerability disclosure
Ordnance Survey publishes a formal vulnerability disclosure policy as one of its governance policies. It is a coordinated-disclosure policy with stated response SLAs and explicit safe-harbour language, but NO bug bounty - OS states plainly that it does not offer monetary rewards. The policy refers to "the published security.txt" as the reporting channel, but no RFC 9116 security.txt is resolvable on any OS host (see well-known/).
Ordnance Survey runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.
Real EstateUnited KingdomLand RegistryGeospatialAddressingOpen DataProperty DataPropTechGovernmentMappingOGCUPRNNational MappingGNSSVector Tiles
Program: Hackerone
security.txt present