Pod Point · Vulnerability Disclosure

Pod Point Vulnerability Disclosure

Vulnerability disclosure

Pod Point runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyUnited KingdomEV ChargingElectric VehiclesUtilitiesElectricityOCPICharge Point OperatorSmart ChargingGrid
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://podenergy.com/security

Source

Vulnerability Disclosure

pod-point-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://podenergy.com/.well-known/security.txt
note: >-
  Pod runs a real, if minimal, vulnerability disclosure programme. Both limbs check
  out: an RFC 9116 security.txt that parses and has not expired, and a live disclosure
  page behind the Contact URI that explicitly invites security researchers. This is the
  single strongest developer-facing signal on the whole Pod estate — notable given
  there is no developer portal, no API documentation and no status page.
policy:
- https://podenergy.com/security
contact:
- https://podenergy.com/security
security_txt:
  url: https://podenergy.com/.well-known/security.txt
  status: 200
  standard: RFC 9116
  file: ../well-known/pod-point-security.txt
  fields:
    Contact: https://podenergy.com/security
    Expires: '2028-03-31T14:00:00.000Z'
    Preferred-Languages: en
    Canonical: https://podenergy.com/.well-known/security.txt
  expired: false
  missing_optional_fields: [Policy, Encryption, Acknowledgments, Hiring, CSAF]
disclosure_page:
  url: https://podenergy.com/security
  status: 200
  invites_researchers: true
  verbatim: >-
    "Found a security vulnerability? Let us know straight away. We work closely with
    the security research community — their work helps keep Pod and our customers safe.
    If you've spotted something, we want to hear from you. We'll work with you to fix
    it fast."
  submission: web form on the page
bug_bounty:
  present: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  note: No bug bounty programme, no public reward schedule and no safe-harbour language found.
safe_harbour: false
disclosure_timeline_published: false
acknowledgements_page: false
evidence:
- source: https://podenergy.com/.well-known/security.txt
  kind: security.txt (live probe)
  status: 200
- source: https://podenergy.com/security
  kind: responsible disclosure page (live probe)
  status: 200
  keywords: [security vulnerability, security research community, fix it fast]
gaps:
- No Policy field in security.txt, so there is no machine-discoverable link to the disclosure terms.
- No published response SLA, disclosure timeline or safe-harbour commitment.
- >-
  security.txt is served from the marketing host only. The API host
  ocpi.podenergy.com returns 404 for /.well-known/security.txt, so a roaming partner
  or researcher working from the API host alone finds no disclosure route.