Report a Vulnerability
If you believe you have found a security vulnerability in an Energy product or service, we want to hear from you.
How to report
Email security@getenergy.com and include:
- A description of the issue.
- The affected product, service, endpoint, or URL.
- Steps to reproduce.
- The potential impact.
- A proof of concept, screenshots, or logs where appropriate.
- A secure way for us to contact you.
Good-faith guidelines
- Avoid privacy violations, harm to others, service disruption, and data loss.
- Use only accounts, systems, and data you are authorized to access.
- Stop testing and notify Energy if you encounter sensitive data.
- Avoid actions that degrade availability.
- Give Energy reasonable time to investigate before any disclosure.
Prohibited activity
- Unauthorized access, modification, deletion, or exfiltration of data.
- Denial-of-service or load testing.
- Social engineering, phishing, physical intrusion, or threats.
- Testing third-party systems.
- Public disclosure before coordination with Energy.