Ssen Vulnerability Disclosure
SSEN publishes no vulnerability-disclosure policy, bug-bounty programme or security.txt of its own on any SSEN-controlled host. The only machine-readable security contact reachable on an SSEN API surface is the RFC 9116 security.txt served on the SSEN Transmission Open Data Portal host — which belongs to Opendatasoft, the platform vendor that operates that portal. It is recorded here because it is the real, reachable disclosure channel for that API host, and it is attributed to the vendor so it is never mistaken for an SSEN programme.
Scottish and Southern Electricity Networks runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.