How to report a security vulnerability

If you believe you have found a security vulnerability in an Allume product, please report it to us so we can investigate and address it.

Please do not publicly disclose the vulnerability or share it on social media, forums or other public channels while we investigate.

Reporting a vulnerability

Channel What happens

Email:
psirt@allumeenergy.com

We aim to acknowledge reports within 3 business days where a contact address has been provided.

We will provide status updates when there is a material change and, where the investigation remains open, aim to provide an update at least every 10 business days.

Complex vulnerabilities, vulnerabilities requiring coordination with third parties, or periods of unusually high report volume may take longer to investigate.

 

Post: Allume Energy (UK) Ltd, 125 Wood Street, London, EC2V 7AW, United Kingdom

If you would prefer not to report by email, you can post a written report to the above address. We aim to acknowledge reports within 3 business days of receipt where a return address has been provided. As with email reports, we will provide status updates when there is a material change and, where the investigation remains open, aim to provide an update at least every 10 business days. Postal reports may take longer to reach us and to process than email reports.


What to include

Please provide as much of the following as you can:

  • Product name and model, such as SolShare 1 or SolShare 2

  • Serial number, firmware or software version, if available

  • A description of the issue

  • The potential impact, if known

  • Steps to reproduce the issue, if available

  • Relevant logs, screenshots or other evidence that can be safely shared

  • Your contact details, if you would like to receive updates (to the extent that we can provide these details to you)

Please keep testing non-destructive and do not access, modify or delete data that does not belong to you.

You do not need to provide your name. If you do not provide contact details, we will not be able to acknowledge your report or provide updates.

Scope

This channel is for suspected security vulnerabilities affecting:

  • SolShare 1 and SolShare 2 hardware and firmware

  • Allume installer and commissioning tools

  • SolCentre

  • Allume-operated services supporting Allume products

  • Allume-provided APIs, interfaces and software

For product support, including installation, commissioning, troubleshooting or non-security-related software and firmware updates, please use our usual support channels.

How long we support this product with security updates

Every SolShare will keep receiving security updates for a set period after it is sold. We will not shorten this period once we have published it.

  • SolShare 1: security updates until 2036 (10 years from the product's last date of sale in the UK).

  • SolShare 2: security updates until 14 August 2031 (5 years from the product's first supply date in the UK).

If we extend a support period, we will update the dates above as soon as we can.

Testing we do not authorise

To protect our customers, people and systems, please do not:

  • Perform denial-of-service (DoS/DDoS) or brute-force attacks

  • Intentionally impair system availability or performance

  • Delete, modify or corrupt data

  • Access or disclose data belonging to other users or customers

  • Conduct phishing, vishing or other social-engineering activities

  • Perform physical testing that could damage equipment, create a safety risk or affect a customer's installation

  • Introduce malware or other malicious software

  • Attempt to maintain persistent access to Allume or customer systems

  • Exploit a vulnerability beyond what is reasonably necessary to demonstrate the issue

You do not need to perform an attack to demonstrate that a product may be vulnerable.

If you inadvertently access data that does not belong to you, stop testing, do not copy or further access the data, and notify us promptly.

Allume does not offer a monetary bug bounty.

Confidentiality and disclosure

Security reports may contain sensitive information. We limit access to people who need the information to investigate and address the issue. Please keep vulnerability information confidential while we investigate and address it.

Where a vulnerability involves a third-party product, we may coordinate with the relevant third party. Where appropriate, we may work with the reporter to agree a disclosure timeline once the issue has been understood and a mitigation or fix is available.

We may publicly disclose information about vulnerabilities where appropriate to protect our customers and users. Where appropriate, we may acknowledge the researcher, subject to their preference.