Security Policy & Coordinated Disclosure

Last updated: 2026 • Enev Networks Ltd

1. Commitment to Cybersecurity

Enev Networks is committed to maintaining the confidentiality, integrity, and availability of our EV charging infrastructure, cloud management platform, and customer billing services. We welcome responsible security research and coordinated vulnerability disclosure from the cybersecurity community.

2. Scope of Disclosure

This policy covers all digital services and platforms operated by Enev Networks, including:

  • enev.energy and official subdomains
  • Public APIs and OCPI 2.2.1 open-data interfaces
  • OCPP 1.6-JSON CSMS endpoints and WebSocket gateways
  • Driver receipt and payment settlement systems

3. Reporting a Vulnerability

If you identify a security vulnerability in our systems, please report it immediately to our dedicated security response team:

Email: security@enev.energy

Please include a description of the issue, affected endpoints, step-by-step reproduction instructions, and proof-of-concept evidence.

4. Ground Rules & Safe Harbor

We request that all security researchers adhere to the following principles:

  • Do not disrupt live charging sessions or interrupt power delivery to electric vehicles.
  • Do not access, modify, or destroy customer or driver personal data (PII).
  • Do not execute denial-of-service (DoS/DDoS) attacks against production infrastructure.
  • Allow reasonable time (minimum 30 days) for remediation before public disclosure.

When acting in good faith in accordance with this policy, Enev Networks considers your research authorized and will not initiate legal action against you.

5. Acknowledgments

Researchers who responsibly report confirmed security vulnerabilities will be recognized on our Security Hall of Fame.