OVO Energy · Vulnerability Disclosure

Ovo Energy Vulnerability Disclosure

Vulnerability disclosure

OVO Energy runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyUnited KingdomUtilitiesElectricityGasSmart MeteringEnergy RetailSolarEV ChargingDemand Response
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://ovo.tines.com/pages/d7e2f76cb5216ff95b0c6c4509524b5b/

Source

Vulnerability Disclosure

ovo-energy-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://www.ovoenergy.com/security
policy:
  - https://www.ovoenergy.com/security
contact:
  - https://ovo.tines.com/pages/d7e2f76cb5216ff95b0c6c4509524b5b/
security_txt:
  url: https://www.ovoenergy.com/.well-known/security.txt
  file: well-known/ovo-energy-security.txt
  expires: '2026-12-31T23:59:59Z'
  canonical: https://www.ovoenergy.com/.well-known/security.txt
  preferred_languages: en
  hiring: https://careers.ovo.com
  encryption: null
  acknowledgements: null
program:
  type: responsible-disclosure
  bug_bounty: false
  bounty_platform: null
  intake: Tines-hosted submission form (no security@ mailbox published)
  scope_statement: >-
    "If you believe you have found a security vulnerability in an OVO Energy
    product or service, please let us know." No formal in-scope / out-of-scope
    asset list, no CVSS matrix and no reward schedule is published.
  report_should_include:
    - A detailed description of the vulnerability
    - Steps to reproduce the issue (proof-of-concept scripts or screenshots)
    - The potential impact of the vulnerability
    - Reporter contact details so OVO can share progress
  commitments:
    - Acknowledge receipt of the report in a timely manner
    - Investigate and provide an estimated timeframe for resolution
    - Notify the reporter when the vulnerability has been fixed
    - >-
      Take no legal action against the reporter, and not ask law enforcement to
      investigate them, provided the reporter complies with the policy
  researcher_guidelines:
    - >-
      Avoid impact to users — do not access, modify or delete OVO Energy customer
      data; only interact with accounts you own or have explicit permission to test
    - >-
      Avoid service disruption — no denial-of-service, spamming, or social
      engineering / phishing against OVO Energy
  safe_harbour: >-
    Conditional. The policy commits to no legal action and no law-enforcement
    referral for reporters who follow the guidelines, but does not use the phrase
    "safe harbor" or cite a standard framework.
evidence:
  - source: https://www.ovoenergy.com/.well-known/security.txt
    kind: security.txt (live probe, HTTP 200, text/plain)
  - source: https://www.ovoenergy.com/security
    kind: responsible-disclosure policy page (live probe, HTTP 200)
notes: >-
  No HackerOne, Bugcrowd or Intigriti programme was found for OVO Energy or OVO
  Group, and no security@ mailbox is published — the only intake is the Tines
  form referenced identically by both security.txt and the policy page. The
  disclosure programme is the strongest published security artefact on the estate.
  No trust centre was found: trust.ovoenergy.com does not resolve, and
  company.ovo.com/trust, company.ovo.com/security, company.ovo.com/compliance and
  www.ovoenergy.com/compliance all return 404, with no named certification
  (SOC 2 / ISO 27001 / PCI DSS / Cyber Essentials) published on any probed page.