Coordinated Vulnerability Disclosure
GreenFlux takes the security of its systems and services seriously. We welcome security researchers who help us identify and responsibly report vulnerabilities in GreenFlux-
owned systems and services.
This policy explains how to report a potential vulnerability to GreenFlux and what you can expect from us.
Reporting a vulnerability
If you believe you have discovered a security vulnerability in a GreenFlux system or service, please report it to:
security@greenflux.com.
Please provide enough information for us to understand and reproduce the issue. Where possible, include:
- A description of the vulnerability.
- The affected system, service, URL or endpoint.
- Steps to reproduce the issue.
- Proof-of-concept code or other supporting material, where relevant.
- The potential impact of the vulnerability.
- Any other information that may help us investigate.
For sensitive vulnerability reports, you can encrypt your report using our PGP public key.
PGP public key:
https://www.greenflux.com/greenflux-security-pgp.asc
PGP fingerprint:
D1DF 6052 6827 D1D5 D33A 2AF4 B662 CC88 B043 9815
Please verify the fingerprint before using the key to encrypt sensitive information.
PGP encryption is optional. You may also submit reports by email without encryption.
Our commitment
GreenFlux will:
- Acknowledge receipt of your report within 3 business days.
- Review and assess reported vulnerabilities.
- Keep you informed where appropriate during the investigation.
- Work to remediate confirmed vulnerabilities within a reasonable timeframe based on their severity and complexity.
- Coordinate with you on disclosure where appropriate.
- Not pursue legal action against researchers who act in good faith and comply with this policy.
Please note that the above does not guarantee that every report will result in a security fix or that a specific remediation timeframe will apply.
Guidelines for security research
When testing GreenFlux systems, please:
- Take reasonable steps to avoid disrupting our services or affecting other users.
- Limit testing to what is necessary to demonstrate the vulnerability.
- Do not access, modify, delete, or exfiltrate data that does not belong to you.
- If you unexpectedly gain access to sensitive data, stop testing and notify us immediately.
- Do not perform denial-of-service or other availability-impacting testing.
- Do not use social engineering, phishing, physical attacks, or attacks against GreenFlux personnel
- Do not intentionally damage systems, data, or services.
- Do not establish persistence or maintain access beyond what is necessary to demonstrate the vulnerability.
- Do not use a vulnerability to obtain financial benefit or otherwise exploit it.
- Keep information about vulnerabilities confidential until GreenFlux has had a reasonable opportunity to investigate and remediate the issue.
Testing must be conducted in a manner that minimises risk to GreenFlux, its customers and other parties.
Scope
This policy applies only to systems and services owned and operated by GreenFlux. This includes GreenFlux internet-facing services and applications that are operated by GreenFlux, where they are reasonably identifiable as GreenFlux systems.
GreenFlux operates a multitenant platform. Testing must not target or attempt to compromise other customers, roaming partners, charge point operators, service providers, or other third-party infrastructure.
The following are not considered part of GreenFlux's scope:
- Systems or applications owned and operated by GreenFlux customers.
- Charge points and charging infrastructure not owned or operated by GreenFlux.
- Roaming partner infrastructure.
- Third-party SaaS platforms and services.
- Third-party infrastructure or services integrated with GreenFlux.
- Physical facilities or equipment.
- Social engineering of GreenFlux employees or contractors.
If you are unsure whether a system is within scope, please contact security@greenflux.com before testing.
Out of scope
The following generally do not qualify as security vulnerabilities unless they demonstrate a clear and meaningful security impact:
- Findings that do not present a realistic security risk.
- Reports based solely on automated scanner output without supporting evidence.
- Missing or incomplete security headers where there is no demonstrated security impact.
- Self-XSS without a realistic attack scenario.
- Rate limiting issues with no demonstrated security consequence.
- Information disclosure involving only publicly available information.
- Best-practice recommendations without a demonstrated vulnerability.
- Reports concerning unsupported or obsolete software or protocols where no exploitable security impact is demonstrated.
GreenFlux may determine that a report is out of scope based on the specific circumstances and potential impact.
Prohibited activities
Researchers must not:
- Conduct denial-of-service or distributed denial-of-service attacks.
- Perform phishing, social engineering, or other attacks against GreenFlux personnel.
- Attempt physical access to GreenFlux facilities or equipment.
- Access or attempt to access another person's account without authorisation.
- Access, modify, delete, or exfiltrate data belonging to other users or customers.
- Target third-party systems or services.
- Use vulnerabilities to cause unnecessary disruption or damage.
- Sell, transfer, or otherwise distribute access obtained through a vulnerability.
- Continue testing after being requested by GreenFlux to stop.
Coordinated disclosure
Please do not publicly disclose a vulnerability before giving GreenFlux a reasonable opportunity to investigate and address it.
If public disclosure is appropriate, GreenFlux will seek to coordinate the timing and content of the disclosure with the researcher.
Researchers are welcome to request acknowledgement or public recognition for their contribution. GreenFlux will only publicly identify a researcher with their consent.
Recognition and rewards
GreenFlux does not currently operate a bug bounty programme and does not offer monetary rewards for vulnerability reports. We may, at our discretion and with the researcher's consent, acknowledge researchers who responsibly report valid vulnerabilities.
Legal safe harbour
GreenFlux will not pursue legal action against researchers who:
- Act in good faith.
- Follow this policy.
- Avoid accessing, modifying, deleting, or exfiltrating data beyond what is necessary to demonstrate the vulnerability.
- Stop testing when requested by GreenFlux.
- Do not intentionally disrupt services or harm GreenFlux, its customers, or third parties.
Activities outside this policy may not be covered by this commitment.
Questions
For questions about this policy or whether proposed security research is within scope, please contact: security@greenflux.com.
Policy updates
GreenFlux may update this policy from time to time. The latest version published on this page is the applicable version.
Last updated: September 2026
