Report a Vulnerability

If you believe you have found a security vulnerability in an Energy product or service, we want to hear from you.

How to report

Email security@getenergy.com and include:

  • A description of the issue.
  • The affected product, service, endpoint, or URL.
  • Steps to reproduce.
  • The potential impact.
  • A proof of concept, screenshots, or logs where appropriate.
  • A secure way for us to contact you.

Good-faith guidelines

  • Avoid privacy violations, harm to others, service disruption, and data loss.
  • Use only accounts, systems, and data you are authorized to access.
  • Stop testing and notify Energy if you encounter sensitive data.
  • Avoid actions that degrade availability.
  • Give Energy reasonable time to investigate before any disclosure.

Prohibited activity

  • Unauthorized access, modification, deletion, or exfiltration of data.
  • Denial-of-service or load testing.
  • Social engineering, phishing, physical intrusion, or threats.
  • Testing third-party systems.
  • Public disclosure before coordination with Energy.

This page is provided for general information and does not amend the applicable agreement. Energy’s practices may vary by product, service, configuration, and region.

Privacy Notice · Terms of Service