Enphase Energy · Vulnerability Disclosure

Enphase Vulnerability Disclosure

Vulnerability disclosure

Enphase Energy runs a coordinated vulnerability disclosure program on Hackerone.

EnergyUnited StatesSolarDERRenewablesBattery StorageEV ChargingDemand ResponseVirtual Power PlantGrid ServicesMicroinvertersHome Energy ManagementSmart MeteringTelemetry
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
policy:
- https://enphase.com/cybersecurity
intake:
- platform: HackerOne
  url: https://docs.hackerone.com/en/articles/8466632-disclosure-assistance
  note: >-
    Enphase routes all vulnerability reports through the HackerOne disclosure-assistance flow. It
    runs no public HackerOne program page - https://hackerone.com/enphase returns 404 - and
    publishes no bounty table or reward range.
contact: []
contact_note: The policy publishes no security@ address; HackerOne is the only intake channel.
scope: >-
  All identified security issues, known or potential, in any Enphase device or system - IoT
  devices, applications, online environments, enterprise systems and websites. That wording covers
  the Enlighten cloud and the developer APIs.
acknowledgement_sla: within five business days
safe_harbour:
  published: true
  researcher_obligations:
  - Notify Enphase promptly on discovery
  - Do not disclose to others pending remediation
  - Respect confidentiality of all information encountered
  - Take no action that harms systems, data availability or user experience
  prohibited:
  - Excessive server impact / load testing
  - Unauthorised access to systems or accounts
  - Modifying or deleting data
  - Denial-of-service attacks
  - Social engineering
advisories:
  url: https://enphase.com/cybersecurity/advisories
  scheme: ENSA-<year>-<n>
  published_ids:
  - ENSA-2026-1
  - ENSA-2024-6
  - ENSA-2024-5
  - ENSA-2024-4
  - ENSA-2024-3
  - ENSA-2024-2
  - ENSA-2024-1
  - ENSA-2023-2
  - ENSA-2023-1
security_commitment:
  url: https://enphase.com/cybersecurity/commitment
  pillars:
  - Security-integrated development
  - Internal and external security testing
  - Partnering with industry on threat assessment and standards
  - Continuous threat and risk analysis
  - Privacy awareness and protection
security_txt:
  published: false
  probes:
  - url: https://enphase.com/.well-known/security.txt
    status: 403
  - url: https://api.enphaseenergy.com/.well-known/security.txt
    status: 404
  - url: https://developer-v4.enphase.com/.well-known/security.txt
    status: 404
  note: >-
    No RFC 9116 security.txt anywhere, so the disclosure policy is discoverable only by browsing
    the marketing site. probe-security-programs.py recorded no hit because enphase.com returns 403
    to non-browser agents; the policy was confirmed by rendered fetch instead.
evidence:
- source: https://enphase.com/cybersecurity
  kind: disclosure-policy
  keywords:
  - responsible disclosure
  - HackerOne
  - vulnerability
- source: https://enphase.com/cybersecurity/advisories
  kind: security-advisories
- source: https://enphase.com/cybersecurity/commitment
  kind: security-commitment
trust_center:
  published: false
  probes:
  - url: https://trust.enphase.com
    status: no DNS
  note: No trust centre and no published SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/enphase-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.