Enphase Energy · Vulnerability Disclosure
Enphase Vulnerability Disclosure
Vulnerability disclosure
Enphase Energy runs a coordinated vulnerability disclosure program on Hackerone.
EnergyUnited StatesSolarDERRenewablesBattery StorageEV ChargingDemand ResponseVirtual Power PlantGrid ServicesMicroinvertersHome Energy ManagementSmart MeteringTelemetry
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-07-27'
method: searched
probe: true
policy:
- https://enphase.com/cybersecurity
intake:
- platform: HackerOne
url: https://docs.hackerone.com/en/articles/8466632-disclosure-assistance
note: >-
Enphase routes all vulnerability reports through the HackerOne disclosure-assistance flow. It
runs no public HackerOne program page - https://hackerone.com/enphase returns 404 - and
publishes no bounty table or reward range.
contact: []
contact_note: The policy publishes no security@ address; HackerOne is the only intake channel.
scope: >-
All identified security issues, known or potential, in any Enphase device or system - IoT
devices, applications, online environments, enterprise systems and websites. That wording covers
the Enlighten cloud and the developer APIs.
acknowledgement_sla: within five business days
safe_harbour:
published: true
researcher_obligations:
- Notify Enphase promptly on discovery
- Do not disclose to others pending remediation
- Respect confidentiality of all information encountered
- Take no action that harms systems, data availability or user experience
prohibited:
- Excessive server impact / load testing
- Unauthorised access to systems or accounts
- Modifying or deleting data
- Denial-of-service attacks
- Social engineering
advisories:
url: https://enphase.com/cybersecurity/advisories
scheme: ENSA-<year>-<n>
published_ids:
- ENSA-2026-1
- ENSA-2024-6
- ENSA-2024-5
- ENSA-2024-4
- ENSA-2024-3
- ENSA-2024-2
- ENSA-2024-1
- ENSA-2023-2
- ENSA-2023-1
security_commitment:
url: https://enphase.com/cybersecurity/commitment
pillars:
- Security-integrated development
- Internal and external security testing
- Partnering with industry on threat assessment and standards
- Continuous threat and risk analysis
- Privacy awareness and protection
security_txt:
published: false
probes:
- url: https://enphase.com/.well-known/security.txt
status: 403
- url: https://api.enphaseenergy.com/.well-known/security.txt
status: 404
- url: https://developer-v4.enphase.com/.well-known/security.txt
status: 404
note: >-
No RFC 9116 security.txt anywhere, so the disclosure policy is discoverable only by browsing
the marketing site. probe-security-programs.py recorded no hit because enphase.com returns 403
to non-browser agents; the policy was confirmed by rendered fetch instead.
evidence:
- source: https://enphase.com/cybersecurity
kind: disclosure-policy
keywords:
- responsible disclosure
- HackerOne
- vulnerability
- source: https://enphase.com/cybersecurity/advisories
kind: security-advisories
- source: https://enphase.com/cybersecurity/commitment
kind: security-commitment
trust_center:
published: false
probes:
- url: https://trust.enphase.com
status: no DNS
note: No trust centre and no published SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/enphase-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.