Coordinated Vulnerability Disclosure

GreenFlux takes the security of its systems and services seriously. We welcome security researchers who help us identify and responsibly report vulnerabilities in GreenFlux-
owned systems and services.

This policy explains how to report a potential vulnerability to GreenFlux and what you can expect from us.

Reporting a vulnerability

If you believe you have discovered a security vulnerability in a GreenFlux system or service, please report it to:
security@greenflux.com.

Please provide enough information for us to understand and reproduce the issue. Where possible, include:

For sensitive vulnerability reports, you can encrypt your report using our PGP public key.

PGP public key:

https://www.greenflux.com/greenflux-security-pgp.asc

PGP fingerprint:

D1DF 6052 6827 D1D5 D33A 2AF4 B662 CC88 B043 9815

Please verify the fingerprint before using the key to encrypt sensitive information.

PGP encryption is optional. You may also submit reports by email without encryption.

Our commitment

GreenFlux will:

Please note that the above does not guarantee that every report will result in a security fix or that a specific remediation timeframe will apply.

Guidelines for security research

When testing GreenFlux systems, please:

Testing must be conducted in a manner that minimises risk to GreenFlux, its customers and other parties.

Scope

This policy applies only to systems and services owned and operated by GreenFlux. This includes GreenFlux internet-facing services and applications that are operated by GreenFlux, where they are reasonably identifiable as GreenFlux systems.

GreenFlux operates a multitenant platform. Testing must not target or attempt to compromise other customers, roaming partners, charge point operators, service providers, or other third-party infrastructure.

The following are not considered part of GreenFlux's scope:

If you are unsure whether a system is within scope, please contact security@greenflux.com before testing.

Out of scope

The following generally do not qualify as security vulnerabilities unless they demonstrate a clear and meaningful security impact:

GreenFlux may determine that a report is out of scope based on the specific circumstances and potential impact.

Prohibited activities

Researchers must not:

Coordinated disclosure

Please do not publicly disclose a vulnerability before giving GreenFlux a reasonable opportunity to investigate and address it.

If public disclosure is appropriate, GreenFlux will seek to coordinate the timing and content of the disclosure with the researcher.

Researchers are welcome to request acknowledgement or public recognition for their contribution. GreenFlux will only publicly identify a researcher with their consent.

Recognition and rewards

GreenFlux does not currently operate a bug bounty programme and does not offer monetary rewards for vulnerability reports. We may, at our discretion and with the researcher's consent, acknowledge researchers who responsibly report valid vulnerabilities.

GreenFlux will not pursue legal action against researchers who:

Activities outside this policy may not be covered by this commitment.

Questions

For questions about this policy or whether proposed security research is within scope, please contact: security@greenflux.com.

Policy updates

GreenFlux may update this policy from time to time. The latest version published on this page is the applicable version.

Last updated: September 2026