generated: '2026-07-27' method: searched probe: true source: https://www.britishgas.co.uk/.well-known/security.txt description: >- British Gas operates a published responsible-disclosure policy, advertised from an RFC 9116 security.txt on the retail supply host. This is the only coordinated-disclosure surface found anywhere in the Centrica group: www.centrica.com serves no security.txt (404) and blocks /security with a WAF 403, and the FieldOps partner platform hosts serve nothing under /.well-known/. There is no bug bounty programme — no HackerOne, Bugcrowd, Intigriti or YesWeHack listing was found for Centrica, British Gas, Bord Gais Energy or Hive — and the security.txt itself omits the RFC 9116 REQUIRED Contact and Expires fields, so it is disclosure signposting rather than a conformant machine-readable record. policy: - https://www.britishgas.co.uk/global-maintenance/responsible-disclosure.html contact: [] bug_bounty: false bug_bounty_platform: null safe_harbor: not stated disclosure_form: >- Reports are submitted through a web form on the responsible-disclosure page; no email address, PGP key or Contact: URI is published. policy_terms: acknowledgement: British Gas states it will acknowledge the submission and review the reported issue. remediation_estimate: An estimate of remediation time is given once an issue is confirmed. public_disclosure: Researchers are asked not to make vulnerability information public. out_of_scope: - Accessible non-sensitive files and directories (README.txt, robots.txt) - Fingerprinting / banner / version disclosure of common public services - Username or email enumeration by brute force or error-message inference prohibited: - Public disclosure of personal, proprietary or financial information - Modification or deletion of data that is not the researcher's own - Interruption, degradation or outage of services (denial of service) - Spamming, social engineering and phishing - Physical exploits or attacks on infrastructure - Local network attacks such as DNS poisoning or ARP spoofing evidence: - source: well-known/centrica-security.txt kind: security.txt status: 200 note: Redirects to https://www.britishgas.co.uk/global-maintenance/security.txt, text/plain. - source: https://www.britishgas.co.uk/global-maintenance/responsible-disclosure.html kind: disclosure-policy-page status: 200 note: Full responsible-disclosure policy with scope, prohibited activity and handling commitments. probes: - url: https://www.centrica.com/.well-known/security.txt status: 404 - url: https://www.centrica.com/security status: 403 note: Corporate WAF blocks the path anonymously. - url: https://api-developer.dev.fieldops.centrica.com/.well-known/security.txt status: 404 - url: https://api.dev.fieldops.centrica.com/.well-known/security.txt status: 404 - url: https://centricaenergy.com/.well-known/security.txt status: 404 - url: https://trust.centrica.com/ status: 000 note: DNS does not resolve.