UK Power Networks · Vulnerability Disclosure
Uk Power Networks Vulnerability Disclosure
Vulnerability disclosure
UK Power Networks runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
EnergyUnited KingdomUtilitiesElectricityGridDistribution NetworkOpen DataSmart MeteringDEREV ChargingCarbonEnergy Markets
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
mailto:security@opendatasoft.com
Source
Vulnerability Disclosure
generated: '2026-06-20'
method: searched
probe: true
source: >-
Live fetch of https://ukpowernetworks.opendatasoft.com/.well-known/security.txt (HTTP 200) and
https://raw.githubusercontent.com/UKPN-DSO/ukpyn/main/SECURITY.md (HTTP 200). Probed 2026-07-27.
summary: >-
A disclosure route exists for both halves of this estate, but neither is UK Power Networks'
own named security programme. The API host serves an RFC 9116 security.txt whose contact is the
platform vendor's (security@opendatasoft.com), and the official SDK repository ships a SECURITY.md
with a responsible-disclosure policy that tells reporters to email "the UK Power Networks team"
without naming an address. UK Power Networks publishes no bug bounty, no dedicated vulnerability
disclosure page for the Open Data Portal, and no security contact of its own that was reachable
anonymously — the corporate host www.ukpowernetworks.co.uk returns HTTP 403 to anonymous
non-browser requests, so absence there is unproven rather than confirmed.
policy:
- https://github.com/UKPN-DSO/ukpyn/blob/main/SECURITY.md
contact:
- mailto:security@opendatasoft.com
bug_bounty:
program: null
platforms_checked: [HackerOne, Bugcrowd, Intigriti]
result: none found
security_txt:
url: https://ukpowernetworks.opendatasoft.com/.well-known/security.txt
http_status: 200
file: well-known/uk-power-networks-security.txt
fields:
Contact: mailto:security@opendatasoft.com
Expires: '2050-01-01T11:00:00.000Z'
Preferred-Languages: en,fr
policy_field: absent
owner: Opendatasoft (the platform vendor), not UK Power Networks
rfc9116: true
note: >-
The Expires value is set 24 years out, which defeats the point of the field — RFC 9116 expects a
date under a year so stale files are detectable. Recorded as observed.
sdk_policy:
url: https://github.com/UKPN-DSO/ukpyn/blob/main/SECURITY.md
http_status: 200
scope: the ukpyn Python client, not the API
reporting:
channel: email
address_published: false
instruction: Do not open a public GitHub issue; email the UK Power Networks team with details.
required_content: [description, steps to reproduce, potential impact, suggested fixes (optional)]
acknowledgement_target: 48 hours
supported_versions: latest only
practices_published:
- No real API keys or secrets in the repository; environment variables for all sensitive configuration
- .env gitignored and never committed
- Placeholder values only in tests, examples and documentation
- Automated dependency scanning and prompt patching
- Input validation on user-supplied data
- Pinned GitHub Action commit SHAs for CodeQL compliance (per the changelog)
gaps:
- No UK Power Networks security contact address is published anywhere reachable anonymously.
- The security.txt on the API host names the platform vendor, so a report about UK Power Networks data would land with Opendatasoft.
- No Policy field in security.txt, so there is no machine-discoverable disclosure policy URL.
- No coordinated disclosure timeline or safe-harbour statement.
evidence:
- source: well-known/uk-power-networks-security.txt
kind: security.txt
http_status: 200
fetched: '2026-07-27'
- source: https://raw.githubusercontent.com/UKPN-DSO/ukpyn/main/SECURITY.md
kind: repository security policy
http_status: 200
fetched: '2026-07-27'
- source: https://www.ukpowernetworks.co.uk/.well-known/security.txt
kind: corporate host probe
http_status: 403
fetched: '2026-07-27'
note: Akamai edge block; absence not confirmed.
related:
well_known: well-known/uk-power-networks-well-known.yml
domain_security: security/uk-power-networks-domain-security.yml
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/uk-power-networks-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.