How we handle a security issue

When you report a security issue, we review it and work with the right teams to understand and address it.

How we handle reports

Step What we do
1. Receive We receive and log the report.
2. Review We look into the issue and understand what it affects.
3. Address We work to resolve the issue or let you know if it is not a security issue.
4. Keep you updated We keep you informed as we work through the issue.
5. Close

We let you know the outcome and close the report.


When you will hear from us

  • Channel: psirt@allumeenergy.com

  • Acknowledgement: We aim to acknowledge your report within 3 business days if you provide contact details.

  • Initial review: We aim to let you know within 10 business days whether we have confirmed the issue, need more information or need more time to investigate.

  • Updates: We will update you when there is a change and aim to provide an update at least every 10 business days while the issue remains open.

  • Closure: We will let you know the outcome when we close the report.

Some issues may take longer to investigate, particularly where other companies or teams need to be involved. If you have not received an acknowledgement by the end of the third business day after reporting an issue, please get in touch with us again, or try info@allumeenergy.com in case your original report did not reach us. Please report suspected vulnerabilities using this template.

Confidentiality

We only share security reports with the people who need them to investigate and address the issue. Please keep the report confidential while we investigate, unless we agree otherwise.

Scope

This process covers security issues affecting SolShare 1 and SolShare 2, installer and commissioning tools, SolCentre, and Allume-operated services supporting Allume products. This process applies globally. Reports are reviewed centrally and sent to the relevant teams to take action.

For ordinary technical support, please use our usual support channels.

How long we support this product

SolShare 1 and SolShare 2 each keep receiving security updates for a set period, published on our How to report a security vulnerability page. We do not shorten a support period once we've published it.