Version: 1
Published: 1 Sept 2026
1. Our Commitment to Security
Enea takes the security of our products and our customers seriously. We value the contribution of independent security researchers and welcome reports of vulnerabilities discovered in good faith. This policy describes what is in scope, how to report a vulnerability to us, and what you can expect from Enea in return.
2. Scope
In Scope
- Enea-owned public-facing digital assets.
- Enea software and service components released or licensed to customers, where the vulnerability can be demonstrated in a supported, publicly available version.
- Third-party and open-source components integrated into an Enea product, where Enea is required to help coordinate disclosure of vulnerabilities in the components it integrates, including with the upstream maintainer.
Out of Scope
- Customers: Please report vulnerability issues through the Customer Support Portal.
- Employees: Please report vulnerability issues through internal security reporting channels.
- Internal Enea projects and systems not intended for public access.
- Standalone third-party products or services which are not integrated into or shipped as part of an Enea product.
- Findings that require physical access, social engineering, or denial-of-service (DoS/DDoS) testing.
3. Safe Harbor
Enea considers security research and vulnerability disclosure activities conducted in accordance with this policy to be authorized. Enea will not pursue legal action against, or support legal action by third parties against, individuals who:
- make a good faith effort to comply with this policy.
- avoid actions that compromise privacy, destroy data, or disrupt or degrade Enea’s products or services.
- promptly report any discovered vulnerability and do not exploit it beyond what is necessary to demonstrate the issue.
If legal action is initiated by a third party against a researcher who has acted in good faith and in accordance with this policy, Enea will make it known that the researcher’s actions were conducted in compliance with this policy.
4. Rules of Engagement
- No denial-of-service (DoS/DDoS) testing.
- No social engineering, phishing, or physical attacks against Enea staff, contractors, or customers.
- Do not access, modify, or delete data that does not belong to you; stop testing and report immediately if you encounter personal data, credentials, or other sensitive information.
- Use only the minimum access or exploitation necessary to reliably demonstrate the vulnerability.
- Comply with all applicable laws and regulations in the country from which you are testing and the country in which the systems are hosted.
- Do not publicly disclose a vulnerability before Enea has had the opportunity to investigate and remediate it (see Section 8, Confidentiality and coordinated disclosure).
- By submitting a vulnerability report to Enea through the channel set out in this policy, you accept that your report will be governed by this policy.
5. How to Report
- Reporting channel: [email protected]. This is Enea’s single point of contact for vulnerability reports, as required by the Cyber Resilience Act.
- Anonymous reports are accepted. You are not required to provide your name, employer, or any contact details to submit a report.
- Language: Reports may be submitted in English.
6. What to Include in Your Report
7. Our Commitment to You
- Acknowledgement: we will acknowledge receipt of your report within 48 hours.
- Status updates: we will provide updates on the progress of remediation at agreed intervals until the issue is resolved.
- Coordinated disclosure timeline: we aim to resolve valid reports within 90 days, or another timeline mutually agreed with the reporter, before any public disclosure.
- Good faith: we will not pursue legal action against researchers who comply with this policy (see Section 3, Safe Harbor).
8. Confidentiality and Coordinated Disclosure
Reporters are asked to keep details of a reported vulnerability confidential until Enea has confirmed that the issue is resolved, or until a disclosure date has been mutually agreed. Enea follows the principle of coordinated vulnerability disclosure: we work with the reporter toward a joint, responsible disclosure of confirmed vulnerabilities. Once a fix is available, Enea will publish information about the fixed vulnerability, including its impact, severity, and remediation guidance, consistent with Annex I, Part II, point (4) of the Cyber Resilience Act.
9. Recognition
A public Hall of Fame for researchers who submit valid, in-scope reports is under consideration and is not yet active.
10. Legal
Submitting a report creates no right, license, payment, employment, or partnership expectation for the reporter, and no obligation on Enea beyond this policy’s stated commitments.
If a report contains material protected by intellectual property rights, the reporter grants Enea a non-exclusive, irrevocable, worldwide, royalty-free license to use, reproduce, and adapt that material to verify, remediate, and disclose the vulnerability, and to meet Enea’s regulatory notification obligations. This license excludes unrelated commercial use and does not transfer ownership of the underlying intellectual property.
This policy does not grant permission to test systems, products, or services outside the scope defined in Section 2.
Enea may update this policy from time to time; the version in effect at the time of your report applies.
About This Page
Classification: Public
Owner: Group CISO
Legal basis: Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 13(6) and Annex I, Part II, points (5) and (6).