generated: '2026-07-26' method: searched probe: true source: https://www.ordnancesurvey.co.uk/governance/policies/vulnerability-disclosure description: >- Ordnance Survey publishes a formal vulnerability disclosure policy as one of its governance policies. It is a coordinated-disclosure policy with stated response SLAs and explicit safe-harbour language, but NO bug bounty - OS states plainly that it does not offer monetary rewards. The policy refers to "the published security.txt" as the reporting channel, but no RFC 9116 security.txt is resolvable on any OS host (see well-known/). policy: - https://www.ordnancesurvey.co.uk/governance/policies/vulnerability-disclosure policy_last_updated: 'June 2024' contact: [] contact_note: >- The policy routes reporters through an on-page "Submit your report" flow and refers to a published security.txt for out-of-band communication. No security@ address is published in the page body. bug_bounty: offered: false statement: >- "We value those who take the time and effort to report security vulnerabilities according to this policy. However, we do not offer monetary rewards for vulnerability disclosures." platform: null platforms_checked: [HackerOne, Bugcrowd, Intigriti] response_commitments: acknowledge: within 5 working days triage: within 10 working days progress_updates: >- OS aims to keep reporters informed; reporters are asked not to chase more than once every 14 days. remediation_notice: >- OS notifies the reporter when the vulnerability is remediated and may invite them to confirm the fix. prioritisation: assessed on impact, severity and exploit complexity public_disclosure: >- Requests to disclose a report are welcomed once the vulnerability is resolved, coordinated with OS. safe_harbour: present: true statement: >- "If legal action is initiated by a third party against you and you have complied with this policy, we can take steps to make it known that your actions were conducted in compliance with this policy." qualified: >- The policy explicitly does not authorise activity inconsistent with the law or that would put OS or partner organisations in breach of legal obligations. scope_rules: must_not: - Break any applicable law or regulations. - Access unnecessary, excessive or significant amounts of data. - Modify data in OS systems or services. - Use high-intensity invasive or destructive scanning tools. - Attempt or report any form of denial of service. - Disrupt OS services or systems. - Report non-exploitable vulnerabilities or "not best practice" findings such as missing security headers. - Report TLS configuration weaknesses such as weak cipher suites or TLS 1.0 support. - Communicate vulnerabilities other than by the means described in the published security.txt. - Social engineer, phish or physically attack OS staff or infrastructure. - Demand financial compensation in order to disclose. must: - Comply with data protection rules and not violate the privacy of OS users, staff, contractors, services or systems. - Not share, redistribute or fail to properly secure data retrieved from OS systems. - >- Securely delete all data retrieved during research as soon as it is no longer required, or within one month of the vulnerability being resolved, whichever occurs first. report_should_include: - The website, IP or page where the vulnerability can be observed. - A brief description of the type of vulnerability. - Benign, non-destructive proof-of-concept steps to reproduce. evidence: - source: https://www.ordnancesurvey.co.uk/governance/policies/vulnerability-disclosure kind: vulnerability-disclosure-policy status: 200 fetched: '2026-07-26' - source: https://www.ordnancesurvey.co.uk/.well-known/security.txt kind: security.txt status: 404 - source: https://api.os.uk/.well-known/security.txt kind: security.txt status: 200 real: false note: api.os.uk catch-all JSON landing document, not a security.txt - source: https://osdatahub.os.uk/.well-known/security.txt kind: security.txt status: 200 real: false note: single-page-app HTML shell gaps: - >- No resolvable RFC 9116 security.txt on any OS host, despite the policy referring to one. This is the single cheapest fix available to OS. - No published security contact email address. - No CVE/advisory feed or security bulletin for the OS Data Hub APIs. related_policies: data_protection: https://www.ordnancesurvey.co.uk/governance/policies/data-protection privacy: https://www.ordnancesurvey.co.uk/governance/policies/privacy