generated: '2026-09-04' method: searched source: https://bp.responsibledisclosure.com/hc/en-us provider: BP providerId: bp description: >- BP operates a coordinated vulnerability disclosure programme for application security issues, hosted on ResponsibleDisclosure.com and operated for BP by the independent third party Synack. program: present: true name: BP Responsible Disclosure url: https://bp.responsibledisclosure.com/hc/en-us scope_url: https://bp.responsibledisclosure.com/hc/en-us/articles/23491597359507-Scope-and-ROE platform: ResponsibleDisclosure.com (Synack) type: vulnerability-disclosure-programme bounty: not stated safe_harbour: >- Researchers must accept the ResponsibleDisclosure.com terms of service. Coordinated disclosure is permitted only after a fix has been issued. scope_summary: >- Application security vulnerabilities only. Explicitly out of scope: non-security bugs, issues affecting only outdated browsers or plugins, and self-XSS (persistent/stored XSS is in scope). Uploading vulnerability or client-related content to third-party utilities is prohibited, and payload data must use professional language. security_txt: present: false detail: >- No /.well-known/security.txt is served. www.bp.com and bp.com return HTTP 403 for the entire /.well-known/ namespace; developer.bp.com and api.developer.bp.com return an SPA shell for every path. The disclosure programme is therefore discoverable only through the web, not through the RFC 9116 mechanism. evidence: - url: https://bp.responsibledisclosure.com/hc/en-us status: 403 note: >- Cloudflare interstitial ("Just a moment... Enable JavaScript and cookies to continue") on an automated fetch. This is a bot challenge, not a dead page — the programme and its Scope/ROE article are publicly indexed and reachable in a browser. - url: https://www.bp.com/.well-known/security.txt status: 403 maintainers: - FN: Kin Lane email: info@apievangelist.com