Policy Statement

We support good‑faith security research aimed at improving the security of Senergy products and services. For individuals or organizations acting in good faith, following this policy, and reporting issues through our official channels, we generally will not initiate legal action.

This safe harbor does not apply to destructive actions, malicious exploitation, data theft, extortion, social engineering/phishing, or activities that cause service unavailability.

Research Boundaries

  • Act in good faith with the goal of improving security;
  • Avoid privacy violations, service disruption, and data destruction;
  • Refrain from social engineering, phishing, spam, or physical attacks;
  • Use only the minimum steps necessary to demonstrate the issue;
  • Report promptly through official channels; and
  • Avoid public disclosure before remediation and coordinated publication, unless otherwise agreed.

Out of Scope Conduct

  • Accessing, modifying, or deleting data that does not belong to you;
  • Intentional service disruption or denial-of-service activity;
  • Exploiting vulnerabilities beyond what is reasonably necessary to demonstrate the issue;
  • Persistence, lateral movement, or privilege escalation in production systems;
  • Physical attacks or hardware tampering unless explicitly authorized in writing; and
  • Any activity that violates applicable law or regulation.

If you are unsure whether a planned research activity is appropriate, please contact us before proceeding at security@senergy.com.

Last updated: [Month DD, YYYY]