generated: '2026-06-20' method: searched probe: true source: >- Live fetch of https://ukpowernetworks.opendatasoft.com/.well-known/security.txt (HTTP 200) and https://raw.githubusercontent.com/UKPN-DSO/ukpyn/main/SECURITY.md (HTTP 200). Probed 2026-07-27. summary: >- A disclosure route exists for both halves of this estate, but neither is UK Power Networks' own named security programme. The API host serves an RFC 9116 security.txt whose contact is the platform vendor's (security@opendatasoft.com), and the official SDK repository ships a SECURITY.md with a responsible-disclosure policy that tells reporters to email "the UK Power Networks team" without naming an address. UK Power Networks publishes no bug bounty, no dedicated vulnerability disclosure page for the Open Data Portal, and no security contact of its own that was reachable anonymously — the corporate host www.ukpowernetworks.co.uk returns HTTP 403 to anonymous non-browser requests, so absence there is unproven rather than confirmed. policy: - https://github.com/UKPN-DSO/ukpyn/blob/main/SECURITY.md contact: - mailto:security@opendatasoft.com bug_bounty: program: null platforms_checked: [HackerOne, Bugcrowd, Intigriti] result: none found security_txt: url: https://ukpowernetworks.opendatasoft.com/.well-known/security.txt http_status: 200 file: well-known/uk-power-networks-security.txt fields: Contact: mailto:security@opendatasoft.com Expires: '2050-01-01T11:00:00.000Z' Preferred-Languages: en,fr policy_field: absent owner: Opendatasoft (the platform vendor), not UK Power Networks rfc9116: true note: >- The Expires value is set 24 years out, which defeats the point of the field — RFC 9116 expects a date under a year so stale files are detectable. Recorded as observed. sdk_policy: url: https://github.com/UKPN-DSO/ukpyn/blob/main/SECURITY.md http_status: 200 scope: the ukpyn Python client, not the API reporting: channel: email address_published: false instruction: Do not open a public GitHub issue; email the UK Power Networks team with details. required_content: [description, steps to reproduce, potential impact, suggested fixes (optional)] acknowledgement_target: 48 hours supported_versions: latest only practices_published: - No real API keys or secrets in the repository; environment variables for all sensitive configuration - .env gitignored and never committed - Placeholder values only in tests, examples and documentation - Automated dependency scanning and prompt patching - Input validation on user-supplied data - Pinned GitHub Action commit SHAs for CodeQL compliance (per the changelog) gaps: - No UK Power Networks security contact address is published anywhere reachable anonymously. - The security.txt on the API host names the platform vendor, so a report about UK Power Networks data would land with Opendatasoft. - No Policy field in security.txt, so there is no machine-discoverable disclosure policy URL. - No coordinated disclosure timeline or safe-harbour statement. evidence: - source: well-known/uk-power-networks-security.txt kind: security.txt http_status: 200 fetched: '2026-07-27' - source: https://raw.githubusercontent.com/UKPN-DSO/ukpyn/main/SECURITY.md kind: repository security policy http_status: 200 fetched: '2026-07-27' - source: https://www.ukpowernetworks.co.uk/.well-known/security.txt kind: corporate host probe http_status: 403 fetched: '2026-07-27' note: Akamai edge block; absence not confirmed. related: well_known: well-known/uk-power-networks-well-known.yml domain_security: security/uk-power-networks-domain-security.yml