generated: '2026-07-27' method: searched probe: true policy: - https://enphase.com/cybersecurity intake: - platform: HackerOne url: https://docs.hackerone.com/en/articles/8466632-disclosure-assistance note: >- Enphase routes all vulnerability reports through the HackerOne disclosure-assistance flow. It runs no public HackerOne program page - https://hackerone.com/enphase returns 404 - and publishes no bounty table or reward range. contact: [] contact_note: The policy publishes no security@ address; HackerOne is the only intake channel. scope: >- All identified security issues, known or potential, in any Enphase device or system - IoT devices, applications, online environments, enterprise systems and websites. That wording covers the Enlighten cloud and the developer APIs. acknowledgement_sla: within five business days safe_harbour: published: true researcher_obligations: - Notify Enphase promptly on discovery - Do not disclose to others pending remediation - Respect confidentiality of all information encountered - Take no action that harms systems, data availability or user experience prohibited: - Excessive server impact / load testing - Unauthorised access to systems or accounts - Modifying or deleting data - Denial-of-service attacks - Social engineering advisories: url: https://enphase.com/cybersecurity/advisories scheme: ENSA-- published_ids: - ENSA-2026-1 - ENSA-2024-6 - ENSA-2024-5 - ENSA-2024-4 - ENSA-2024-3 - ENSA-2024-2 - ENSA-2024-1 - ENSA-2023-2 - ENSA-2023-1 security_commitment: url: https://enphase.com/cybersecurity/commitment pillars: - Security-integrated development - Internal and external security testing - Partnering with industry on threat assessment and standards - Continuous threat and risk analysis - Privacy awareness and protection security_txt: published: false probes: - url: https://enphase.com/.well-known/security.txt status: 403 - url: https://api.enphaseenergy.com/.well-known/security.txt status: 404 - url: https://developer-v4.enphase.com/.well-known/security.txt status: 404 note: >- No RFC 9116 security.txt anywhere, so the disclosure policy is discoverable only by browsing the marketing site. probe-security-programs.py recorded no hit because enphase.com returns 403 to non-browser agents; the policy was confirmed by rendered fetch instead. evidence: - source: https://enphase.com/cybersecurity kind: disclosure-policy keywords: - responsible disclosure - HackerOne - vulnerability - source: https://enphase.com/cybersecurity/advisories kind: security-advisories - source: https://enphase.com/cybersecurity/commitment kind: security-commitment trust_center: published: false probes: - url: https://trust.enphase.com status: no DNS note: No trust centre and no published SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation.