Skip to content Skip to footer

Security and Vulnerabilities 

Security and Vulnerabilities 

Background

At myenergi, we are committed to designing products that are safe, secure, and reliable. Our products incorporate security features to help protect them against evolving cyber threats, and we provide security updates for our supported products to address identified vulnerabilities and maintain product security.

As cyber threats continue to evolve, we recommend keeping all myenergi devices updated with the latest firmware releases. Installing updates ensures you benefit from the latest security enhancements, performance improvements, and product features. Information about current firmware versions and release notes can be found in our support centre: Current firmware versions / updating your firmware – Help Centre GB (myenergi.com).

Vulnerability Disclosure Policy

This vulnerability disclosure policy applies to any vulnerabilities you are considering reporting to us (myenergi). We recommend reading this vulnerability disclosure policy fully before you report a vulnerability and always acting in compliance with it. We value those who take the time and effort to report security vulnerabilities according to this policy, but we do not offer monetary rewards for vulnerability disclosures.

Legal Obligations

This policy forms part of myenergi’s compliance with applicable product security legislation, including the:

  • UK’s Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 (for devices in the UK)

 

  • Australia’s Cyber Security (Security Standards for Smart Devices) Rules 2025 authorised by the Cyber Security Act

Statements of Compliance for our products and other relevant documentation can be accessed through our Compliance Download Centre.

Reporting

If you believe you have found a security vulnerability, please submit your report to us using our Submit a Vulnerability Report | myenergi GB or if unavailable email infosec@myenergi.com.

In your report please include details of:

  • Your name and contact email (optional)
  • The vulnerability or security concern, and potential impact
  • The myenergi products affected (e.g., firmware / software versions, webpages, devices)
  • Steps taken to discover or identify the security issue or vulnerability
  • Any relevant Common Vulnerability and Exposures (CVEs), see https://cve.mitre.org/ for further information
  • Geographic location of the affected system, application, device, or data (if known)
  • Supporting information

The information should be benign, non-destructive, and limited to that necessary to demonstrate the vulnerability. This enables efficient triage of reports, helps identify duplicate submissions, and reduces the risk of vulnerabilities being maliciously exploited.

For the safety and security of our products and customers, we do not disclose information relating to security vulnerabilities until a suitable fix has been implemented and we ask researchers to provide us with a reasonable opportunity to investigate and remediate vulnerabilities before public disclosure.

What to expect

After you have submitted your report, we will:

  • Acknowledge receipt of the report within 7 days
  • Provide an initial status update within 21 days
  • Provide reasonable progress updates while the issue remains under investigation
  • Continue to provide updates until the reported issue is resolved, or otherwise closed
  • Provide responses in English and free of charge
  • Notify the relevant authorities within legal timescales as appropriate

Our commitment to you:

  • We’re grateful for the support from the security research community
  • We will not take legal action against you for disclosing a vulnerability to us provided you have acted in good faith, avoided privacy violations and service disruptions, and not exploited any vulnerability beyond what was necessary for verification
  • We’ll investigate your report, and keep you informed until the resolution of the reported vulnerability
  • We’ll acknowledge your efforts and support (if desired) in any release notes

Acting within the law

Please ensure you act in a lawful manner when interacting with our products, websites, or servers. The following is prohibited. This is not an exhaustive list, and you should always consider the current legislation:

  • Any activity outside of the law
  • The use of aggressive or invasive automated scanning tools, such as port scanners or vulnerability scanners
  • Creating server demand which could result in a Denial of Service
  • Social engineering our customers, staff, or suppliers
  • Breaching data protection legislation by exposing or accessing the data of customers, staff, or suppliers
  • Uploading malicious payloads to our products or services
myenergi