generated: '2026-07-27' method: searched probe: true source: https://podenergy.com/.well-known/security.txt note: >- Pod runs a real, if minimal, vulnerability disclosure programme. Both limbs check out: an RFC 9116 security.txt that parses and has not expired, and a live disclosure page behind the Contact URI that explicitly invites security researchers. This is the single strongest developer-facing signal on the whole Pod estate — notable given there is no developer portal, no API documentation and no status page. policy: - https://podenergy.com/security contact: - https://podenergy.com/security security_txt: url: https://podenergy.com/.well-known/security.txt status: 200 standard: RFC 9116 file: ../well-known/pod-point-security.txt fields: Contact: https://podenergy.com/security Expires: '2028-03-31T14:00:00.000Z' Preferred-Languages: en Canonical: https://podenergy.com/.well-known/security.txt expired: false missing_optional_fields: [Policy, Encryption, Acknowledgments, Hiring, CSAF] disclosure_page: url: https://podenergy.com/security status: 200 invites_researchers: true verbatim: >- "Found a security vulnerability? Let us know straight away. We work closely with the security research community — their work helps keep Pod and our customers safe. If you've spotted something, we want to hear from you. We'll work with you to fix it fast." submission: web form on the page bug_bounty: present: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] note: No bug bounty programme, no public reward schedule and no safe-harbour language found. safe_harbour: false disclosure_timeline_published: false acknowledgements_page: false evidence: - source: https://podenergy.com/.well-known/security.txt kind: security.txt (live probe) status: 200 - source: https://podenergy.com/security kind: responsible disclosure page (live probe) status: 200 keywords: [security vulnerability, security research community, fix it fast] gaps: - No Policy field in security.txt, so there is no machine-discoverable link to the disclosure terms. - No published response SLA, disclosure timeline or safe-harbour commitment. - >- security.txt is served from the marketing host only. The API host ocpi.podenergy.com returns 404 for /.well-known/security.txt, so a roaming partner or researcher working from the API host alone finds no disclosure route.