Enphase Energy · Vulnerability Disclosure

Enphase Vulnerability Disclosure

Vulnerability disclosure

Enphase Energy runs a coordinated vulnerability disclosure program on Hackerone.

EnergyUnited StatesSolarDERRenewablesBattery StorageEV ChargingDemand ResponseVirtual Power PlantGrid ServicesMicroinvertersHome Energy ManagementSmart MeteringTelemetry
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
policy:
- https://enphase.com/cybersecurity
intake:
- platform: HackerOne
  url: https://docs.hackerone.com/en/articles/8466632-disclosure-assistance
  note: >-
    Enphase routes all vulnerability reports through the HackerOne disclosure-assistance flow. It
    runs no public HackerOne program page - https://hackerone.com/enphase returns 404 - and
    publishes no bounty table or reward range.
contact: []
contact_note: The policy publishes no security@ address; HackerOne is the only intake channel.
scope: >-
  All identified security issues, known or potential, in any Enphase device or system - IoT
  devices, applications, online environments, enterprise systems and websites. That wording covers
  the Enlighten cloud and the developer APIs.
acknowledgement_sla: within five business days
safe_harbour:
  published: true
  researcher_obligations:
  - Notify Enphase promptly on discovery
  - Do not disclose to others pending remediation
  - Respect confidentiality of all information encountered
  - Take no action that harms systems, data availability or user experience
  prohibited:
  - Excessive server impact / load testing
  - Unauthorised access to systems or accounts
  - Modifying or deleting data
  - Denial-of-service attacks
  - Social engineering
advisories:
  url: https://enphase.com/cybersecurity/advisories
  scheme: ENSA-<year>-<n>
  published_ids:
  - ENSA-2026-1
  - ENSA-2024-6
  - ENSA-2024-5
  - ENSA-2024-4
  - ENSA-2024-3
  - ENSA-2024-2
  - ENSA-2024-1
  - ENSA-2023-2
  - ENSA-2023-1
security_commitment:
  url: https://enphase.com/cybersecurity/commitment
  pillars:
  - Security-integrated development
  - Internal and external security testing
  - Partnering with industry on threat assessment and standards
  - Continuous threat and risk analysis
  - Privacy awareness and protection
security_txt:
  published: false
  probes:
  - url: https://enphase.com/.well-known/security.txt
    status: 403
  - url: https://api.enphaseenergy.com/.well-known/security.txt
    status: 404
  - url: https://developer-v4.enphase.com/.well-known/security.txt
    status: 404
  note: >-
    No RFC 9116 security.txt anywhere, so the disclosure policy is discoverable only by browsing
    the marketing site. probe-security-programs.py recorded no hit because enphase.com returns 403
    to non-browser agents; the policy was confirmed by rendered fetch instead.
evidence:
- source: https://enphase.com/cybersecurity
  kind: disclosure-policy
  keywords:
  - responsible disclosure
  - HackerOne
  - vulnerability
- source: https://enphase.com/cybersecurity/advisories
  kind: security-advisories
- source: https://enphase.com/cybersecurity/commitment
  kind: security-commitment
trust_center:
  published: false
  probes:
  - url: https://trust.enphase.com
    status: no DNS
  note: No trust centre and no published SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation.