generated: '2026-07-27' method: searched probe: true source: https://www.ovoenergy.com/security policy: - https://www.ovoenergy.com/security contact: - https://ovo.tines.com/pages/d7e2f76cb5216ff95b0c6c4509524b5b/ security_txt: url: https://www.ovoenergy.com/.well-known/security.txt file: well-known/ovo-energy-security.txt expires: '2026-12-31T23:59:59Z' canonical: https://www.ovoenergy.com/.well-known/security.txt preferred_languages: en hiring: https://careers.ovo.com encryption: null acknowledgements: null program: type: responsible-disclosure bug_bounty: false bounty_platform: null intake: Tines-hosted submission form (no security@ mailbox published) scope_statement: >- "If you believe you have found a security vulnerability in an OVO Energy product or service, please let us know." No formal in-scope / out-of-scope asset list, no CVSS matrix and no reward schedule is published. report_should_include: - A detailed description of the vulnerability - Steps to reproduce the issue (proof-of-concept scripts or screenshots) - The potential impact of the vulnerability - Reporter contact details so OVO can share progress commitments: - Acknowledge receipt of the report in a timely manner - Investigate and provide an estimated timeframe for resolution - Notify the reporter when the vulnerability has been fixed - >- Take no legal action against the reporter, and not ask law enforcement to investigate them, provided the reporter complies with the policy researcher_guidelines: - >- Avoid impact to users — do not access, modify or delete OVO Energy customer data; only interact with accounts you own or have explicit permission to test - >- Avoid service disruption — no denial-of-service, spamming, or social engineering / phishing against OVO Energy safe_harbour: >- Conditional. The policy commits to no legal action and no law-enforcement referral for reporters who follow the guidelines, but does not use the phrase "safe harbor" or cite a standard framework. evidence: - source: https://www.ovoenergy.com/.well-known/security.txt kind: security.txt (live probe, HTTP 200, text/plain) - source: https://www.ovoenergy.com/security kind: responsible-disclosure policy page (live probe, HTTP 200) notes: >- No HackerOne, Bugcrowd or Intigriti programme was found for OVO Energy or OVO Group, and no security@ mailbox is published — the only intake is the Tines form referenced identically by both security.txt and the policy page. The disclosure programme is the strongest published security artefact on the estate. No trust centre was found: trust.ovoenergy.com does not resolve, and company.ovo.com/trust, company.ovo.com/security, company.ovo.com/compliance and www.ovoenergy.com/compliance all return 404, with no named certification (SOC 2 / ISO 27001 / PCI DSS / Cyber Essentials) published on any probed page.