generated: '2026-07-27' method: searched probe: true description: >- A vulnerability-reporting route exists for this API, but it belongs to the platform vendor rather than to the network operator. The Opendatasoft (Huwise) tenant that serves the SP Electricity North West open data API publishes an RFC 9116 security.txt at the API host root, and the vendor's security page names a security team address and describes an incident-handling process. Electricity North West itself publishes nothing reachable: www.enwl.co.uk sits behind a Cloudflare managed challenge that returns HTTP 403 to every non-browser client, so its /.well-known/security.txt could not be retrieved or ruled out. policy: - https://www.huwise.com/en/security/ contact: - mailto:security@opendatasoft.com - mailto:security@huwise.com security_txt: url: https://electricitynorthwest.opendatasoft.com/.well-known/security.txt status: 200 rfc: RFC 9116 file: well-known/electricity-north-west-security.txt fields: Contact: mailto:security@opendatasoft.com Expires: '2050-01-01T11:00:00.000Z' Preferred-Languages: en,fr gaps: - >- No "Policy:" field — the file points at a mailbox, not a written disclosure policy. - 'No "Encryption:", "Acknowledgments:" or "Hiring:" fields.' - >- Expires is set to 2050-01-01, far beyond the RFC 9116 recommendation of no more than a year out. bug_bounty: program: null platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: false disclosure_program: documented: true url: https://www.huwise.com/en/security/ operated_by: Opendatasoft SAS (Huwise) — platform vendor quotes: - >- "If you wish to report a security vulnerability, you can contact Huwise's security team at security@huwise.com." - >- "In case of a security incident, Huwise has put in place a process and organizational structure to deal with security incidents as quickly as possible." related_practices: - Regular third-party penetration testing programme. - Daily security inspection of servers and software for known vulnerabilities. - Major-impact vulnerabilities patched "usually within one day". - Passwords stored hashed with PBKDF2. security_policy_basis: >- The vendor states its information-security policy "is based on the ISO 27001 and ISO 27002 standards". That is a statement of basis, NOT a certification claim — no certificate, audit report, SOC 2, PCI, HIPAA or FedRAMP attestation is named anywhere on the page. Recorded as such; no Compliance pointer is emitted for it. provider_own_surface: domain: enwl.co.uk security_txt_status: 403 note: >- Cloudflare managed challenge blocks all non-browser requests to www.enwl.co.uk, including /.well-known/security.txt, /robots.txt and /favicon.ico. This is an inability to observe, not a confirmed absence. data_portal_contact: dataportal@enwl.co.uk evidence: - source: https://electricitynorthwest.opendatasoft.com/.well-known/security.txt kind: security.txt status: 200 date: '2026-07-27' - source: https://www.huwise.com/en/security/ kind: security page status: 200 date: '2026-07-27' keywords: [security@huwise.com, vulnerability, penetration testing, security incident, ISO 27001] - source: https://www.enwl.co.uk/.well-known/security.txt kind: security.txt status: 403 date: '2026-07-27'