Ordnance Survey · Vulnerability Disclosure

Ordnance Survey Vulnerability Disclosure

Vulnerability disclosure

Ordnance Survey publishes a formal vulnerability disclosure policy as one of its governance policies. It is a coordinated-disclosure policy with stated response SLAs and explicit safe-harbour language, but NO bug bounty - OS states plainly that it does not offer monetary rewards. The policy refers to "the published security.txt" as the reporting channel, but no RFC 9116 security.txt is resolvable on any OS host (see well-known/).

Ordnance Survey runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

Real EstateUnited KingdomLand RegistryGeospatialAddressingOpen DataProperty DataPropTechGovernmentMappingOGCUPRNNational MappingGNSSVector Tiles
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: https://www.ordnancesurvey.co.uk/governance/policies/vulnerability-disclosure
description: >-
  Ordnance Survey publishes a formal vulnerability disclosure policy as one of
  its governance policies. It is a coordinated-disclosure policy with stated
  response SLAs and explicit safe-harbour language, but NO bug bounty - OS
  states plainly that it does not offer monetary rewards. The policy refers to
  "the published security.txt" as the reporting channel, but no RFC 9116
  security.txt is resolvable on any OS host (see well-known/).
policy:
  - https://www.ordnancesurvey.co.uk/governance/policies/vulnerability-disclosure
policy_last_updated: 'June 2024'
contact: []
contact_note: >-
  The policy routes reporters through an on-page "Submit your report" flow and
  refers to a published security.txt for out-of-band communication. No
  security@ address is published in the page body.
bug_bounty:
  offered: false
  statement: >-
    "We value those who take the time and effort to report security
    vulnerabilities according to this policy. However, we do not offer monetary
    rewards for vulnerability disclosures."
  platform: null
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
response_commitments:
  acknowledge: within 5 working days
  triage: within 10 working days
  progress_updates: >-
    OS aims to keep reporters informed; reporters are asked not to chase more
    than once every 14 days.
  remediation_notice: >-
    OS notifies the reporter when the vulnerability is remediated and may
    invite them to confirm the fix.
  prioritisation: assessed on impact, severity and exploit complexity
  public_disclosure: >-
    Requests to disclose a report are welcomed once the vulnerability is
    resolved, coordinated with OS.
safe_harbour:
  present: true
  statement: >-
    "If legal action is initiated by a third party against you and you have
    complied with this policy, we can take steps to make it known that your
    actions were conducted in compliance with this policy."
  qualified: >-
    The policy explicitly does not authorise activity inconsistent with the law
    or that would put OS or partner organisations in breach of legal obligations.
scope_rules:
  must_not:
    - Break any applicable law or regulations.
    - Access unnecessary, excessive or significant amounts of data.
    - Modify data in OS systems or services.
    - Use high-intensity invasive or destructive scanning tools.
    - Attempt or report any form of denial of service.
    - Disrupt OS services or systems.
    - Report non-exploitable vulnerabilities or "not best practice" findings such as missing security headers.
    - Report TLS configuration weaknesses such as weak cipher suites or TLS 1.0 support.
    - Communicate vulnerabilities other than by the means described in the published security.txt.
    - Social engineer, phish or physically attack OS staff or infrastructure.
    - Demand financial compensation in order to disclose.
  must:
    - Comply with data protection rules and not violate the privacy of OS users, staff, contractors, services or systems.
    - Not share, redistribute or fail to properly secure data retrieved from OS systems.
    - >-
      Securely delete all data retrieved during research as soon as it is no
      longer required, or within one month of the vulnerability being resolved,
      whichever occurs first.
  report_should_include:
    - The website, IP or page where the vulnerability can be observed.
    - A brief description of the type of vulnerability.
    - Benign, non-destructive proof-of-concept steps to reproduce.
evidence:
  - source: https://www.ordnancesurvey.co.uk/governance/policies/vulnerability-disclosure
    kind: vulnerability-disclosure-policy
    status: 200
    fetched: '2026-07-26'
  - source: https://www.ordnancesurvey.co.uk/.well-known/security.txt
    kind: security.txt
    status: 404
  - source: https://api.os.uk/.well-known/security.txt
    kind: security.txt
    status: 200
    real: false
    note: api.os.uk catch-all JSON landing document, not a security.txt
  - source: https://osdatahub.os.uk/.well-known/security.txt
    kind: security.txt
    status: 200
    real: false
    note: single-page-app HTML shell
gaps:
  - >-
    No resolvable RFC 9116 security.txt on any OS host, despite the policy
    referring to one. This is the single cheapest fix available to OS.
  - No published security contact email address.
  - No CVE/advisory feed or security bulletin for the OS Data Hub APIs.
related_policies:
  data_protection: https://www.ordnancesurvey.co.uk/governance/policies/data-protection
  privacy: https://www.ordnancesurvey.co.uk/governance/policies/privacy