Vulnerability disclosure policy
The security of our customers and systems is our highest priority. We value the work of the security community and encourage the responsible disclosure of vulnerabilities.
By submitting a report, you agree to comply with the terms and rules outlined below. Adherence to these terms is a requirement for safe harbour status. Unauthorised actions outside these guidelines may result in legal or disciplinary action.
Our commitment toyour safe harbour
If you comply with this policy during your security research, we commit to the following:
Authorisation
We consider your research to be authorised and helpful to the safety of our users.
Legal protection
We will not initiate legal action against you.
Transparency
We will work with you to understand the issue and provide updates during the remediation process.
Rules of engagement
No disruption
Do not perform testing that degrades, disrupts, or compromises the availability of any service (e.g. disk operating system) or impacts OVO customers.
Data privacy
If you encounter personally identifiable information or payment card industry data, stop immediately. Do not view, download, or alter any data beyond what is strictly necessary to prove the existence of the vulnerability (e.g. capturing a masked screenshot).
Confidentiality
You must maintain full confidentiality. Do not disclose vulnerability details or the existence of a report outside of the designated reporting channel below.
No social engineering
Do not target OVO employees, contractors, or customers with phishing, vishing, or physical attacks.
Scope
Only the assets listed as in-scope are authorised for testing. Any assets not listed here are strictly excluded.
In-scope assets. Research is authorised on the following root domains and their subdomains.
Out-of-scope assets. These domains are excluded from this policy.
| In-scope assets | Out-of-scope assets |
|---|---|
*.boostpower.co.uk | appsfwd.ovoenergy.com |
.corgihomeheat.co.uk | askovo.net |
*.corgihomeplan.co.uk | auth-retail.ovoenergy.com |
*.corgihomeplan.uk | auth-www.ovoenergy.com |
*.gridsvc.net | cctv-mgr.ovoenergy.com |
*.ovo.com | cev.ovoenergy.com |
.ovoenergy.com | documentum.ovoenergy.com |
*.ovoener.gy | ecomms.ovoenergy.com |
*.ovotech.org.uk | fortivpn.ovoenergy.com |
*.ovo-live.com | forum.ovoenergy.com |
*.ovo-sso.com | greeninstaller.co.uk |
*.ovoener.gy | hackable-lenny.com |
hackable-sarge.com | |
hackable-slink.com | |
hackable-woody.com | |
learn.ovo.com | |
lightning.ovoenergy.com | |
oisl.gg | |
ovo-comms.co.uk | |
ovo-comms-uat.co.uk | |
ovobyus.com | |
ovocards.com | |
ovocommunity.com | |
ovofoundation.org.uk | |
ovomyrewards.com | |
paybylink.ovoenergy.com | |
pma.ovoenergy.com | |
survey.ovoenergy.com | |
tech.ovoenergy.com | |
testrailapp.ovoenergy.com | |
tracking.ovo.com |
Recognition
OVO does not currently operate a paid bug bounty programme. We do not offer financial compensation, gift vouchers, or merchandise in exchange for reported vulnerabilities.