Vulnerability disclosure policy

The security of our customers and systems is our highest priority. We value the work of the security community and encourage the responsible disclosure of vulnerabilities.

By submitting a report, you agree to comply with the terms and rules outlined below. Adherence to these terms is a requirement for safe harbour status. Unauthorised actions outside these guidelines may result in legal or disciplinary action.

hero image

Our commitment toyour safe harbour

If you comply with this policy during your security research, we commit to the following:

Authorisation

Authorisation

We consider your research to be authorised and helpful to the safety of our users.

Legal protection

Legal protection

Transparency

Transparency

We will work with you to understand the issue and provide updates during the remediation process.

Rules ofengagement

info-card-graphic

No disruption

Do not perform testing that degrades, disrupts, or compromises the availability of any service (e.g. disk operating system) or impacts OVO customers.

info-card-graphic

Data privacy

If you encounter personally identifiable information or payment card industry data, stop immediately. Do not view, download, or alter any data beyond what is strictly necessary to prove the existence of the vulnerability (e.g. capturing a masked screenshot).

info-card-graphic

Confidentiality

You must maintain full confidentiality. Do not disclose vulnerability details or the existence of a report outside of the designated reporting channel below.

info-card-graphic

No social engineering

Do not target OVO employees, contractors, or customers with phishing, vishing, or physical attacks.

Scope

Only the assets listed as in-scope are authorised for testing.
Any assets not listed here are strictly excluded.

  • In-scope assets. Research is authorised on the following root domains
and their subdomains.

  • Out-of-scope assets. These domains are excluded from this policy.

In-scope assetsOut-of-scope assets

*.boostpower.co.uk

appsfwd.ovoenergy.com

.corgihomeheat.co.uk

askovo.net

*.corgihomeplan.co.uk

auth-retail.ovoenergy.com

*.corgihomeplan.uk

auth-www.ovoenergy.com

*.gridsvc.net

cctv-mgr.ovoenergy.com

*.ovo.com

cev.ovoenergy.com

.ovoenergy.com

documentum.ovoenergy.com

*.ovoener.gy

ecomms.ovoenergy.com

*.ovotech.org.uk

fortivpn.ovoenergy.com

*.ovo-live.com

forum.ovoenergy.com

*.ovo-sso.com

greeninstaller.co.uk

*.ovoener.gy

hackable-lenny.com

hackable-sarge.com

hackable-slink.com

hackable-woody.com

learn.ovo.com

lightning.ovoenergy.com

oisl.gg

ovo-comms.co.uk

ovo-comms-uat.co.uk

ovobyus.com

ovocards.com

ovocommunity.com

ovofoundation.org.uk

ovomyrewards.com

paybylink.ovoenergy.com

pma.ovoenergy.com

survey.ovoenergy.com

tech.ovoenergy.com

testrailapp.ovoenergy.com

tracking.ovo.com

Recognition

OVO does not currently operate a paid bug bounty programme. We do not offer financial compensation, gift vouchers, or merchandise in exchange for reported vulnerabilities.

Agreement