generated: '2026-07-27' method: searched probe: true source: https://northernpowergrid.opendatasoft.com/.well-known/security.txt note: >- The security.txt served on the API/portal host is the platform operator's, not Northern Powergrid's — it names security@opendatasoft.com. That is still the correct, machine-discoverable disclosure route for a vulnerability found in this API surface, because the surface is an Opendatasoft-hosted tenant. No Northern Powergrid-authored disclosure policy, bug bounty or security@ address could be reached: the corporate site www.northernpowergrid.com geo-blocks all non-UK requests with a 403 interstitial, so its /security, /responsible-disclosure and /.well-known/ paths could not be probed from here. That is recorded as a blocked probe, not as an absence. policy: [] contact: - mailto:security@opendatasoft.com security_txt: url: https://northernpowergrid.opendatasoft.com/.well-known/security.txt file: well-known/northern-powergrid-security.txt status: 200 standard: RFC 9116 expires: '2050-01-01T11:00:00.000Z' preferred_languages: [en, fr] published_by: Opendatasoft (platform operator) bug_bounty: program: null platforms_checked: [hackerone, bugcrowd, intigriti] result: none found evidence: - source: well-known/northern-powergrid-security.txt kind: security.txt url: https://northernpowergrid.opendatasoft.com/.well-known/security.txt status: 200 blocked_probes: - url: https://www.northernpowergrid.com/.well-known/security.txt status: 403 reason: geo-blocked outside the United Kingdom