Security

Report a security issue

Gridome runs in people's homes and controls real electrical equipment. If you have found a security issue, we want to hear about it. Write to security@gridome.energy.

How to report

Send your report to security@gridome.energy. Please include, as far as you can:

  • what the issue is, and which part of Gridome it affects;
  • the steps to reproduce it, ideally with the smallest proof you can make;
  • the version affected. The app shows it in Settings, under Your Gridome;
  • what an attacker gets, and what they need in order to get it;
  • how you would like to be credited, or that you prefer not to be.

Write in English or Polish. If the details are sensitive, send a first message with no details in it, and we will agree a channel with you before you send anything else.

What we commit to

  • Acknowledgement: within 5 working days.
  • First assessment: whether we can reproduce it, and our first view of how severe it is, within 10 working days of acknowledgement.
  • Status updates: at least every 30 days while the report is open, without you having to ask.
  • Resolution: we aim to make a fix available to affected devices within 90 days of acknowledgement. Where that is not possible, we say so, say why, and agree a new date with you.
  • Disclosure: coordinated, 90 days from acknowledgement by default, and earlier by agreement once a fix has reached customers.
  • Credit: named in the release notes if you want it, anonymous if you prefer.

If a vulnerability is being actively exploited, we act at once, ship a fix outside the normal schedule, and tell affected customers what happened.

There is no bug bounty. We do not pay for reports. We say so up front so nobody spends time expecting otherwise.

Security updates, and for how long

Security updates reach your Gridome through its signed update channel. They are free, and they are never held behind a paid plan.

Gridome receives security updates for five years from the date a unit is placed on the market. Five years is a minimum, not a ceiling. It can be extended, and an extension also applies to units already sold. It will never be shortened for a unit that is already in somebody's home.

In scope

Security issues in anything Gridome builds and ships:

  • the software on the Gridome Orchestrator, including its local dashboard and the phone app;
  • software updates: how they are signed, delivered and installed;
  • setup: the setup network, the setup code on the label, the setup page and the first sign-in;
  • remote access: how your Gridome connects out, and how phones are approved;
  • the Gridome remote-access service and its public endpoints;
  • this website.

Out of scope

  • Equipment you connect to Gridome, such as inverters, batteries, smart plugs, meters, heat pumps and car chargers. Please report those to their maker. Tell us as well if Gridome could limit the effect, and we will help.
  • Services we use as a customer, such as our hosting and network providers. Report those through the provider's own programme.
  • Findings that need a unit to be opened up and that recover only that unit's own secrets, when the unit belongs to the person reporting.
  • Attacks that need an administrator who is already signed in, unless they cross into another user's rights or another household.
  • Denial of service by flooding traffic.
  • Scanner output with no demonstrated impact, such as missing headers on pages without a session, TLS preferences with no exploitable consequence, missing mail records on domains that send no mail, or version banners.
  • Social engineering of our staff, customers or installers.
  • Anything that needs access to data or equipment belonging to someone else.

Safe harbour for good-faith research

If you research in good faith under this policy, we will not start or support legal action against you. If someone else does, we will say publicly that your work was authorised under this policy. Good faith means that:

  • you test only a device you own or control, or one you have been given permission to test;
  • you do not access, copy, change or delete anyone else's data. If you come across it by accident, you stop, keep none of it, and tell us;
  • you do not degrade service for other people, and you do not run load tests against our service or this website;
  • you never operate real electrical equipment that belongs to someone else. Gridome controls real batteries, inverters and car chargers. This is the one place where a careless proof of concept has physical consequences in somebody's home;
  • you give us a fair chance to fix the issue before you disclose it, on the timetable above;
  • you do not use the finding for extortion, and you do not sell it.

This policy cannot waive the rights of other people, and it does not authorise anything unlawful.

How we handle a report

  • It is logged on the day it arrives, with a named owner.
  • We reproduce it and rate it. The question that drives the rating is simple: what can an attacker do to a household, and what do they need to do it?
  • The fix comes with a test that fails without it.
  • The fix ships through the normal signed update channel.
  • You receive the fixed version and its release note before anyone else is told.
  • Where the law requires us to notify a national authority, we do. Under the EU Cyber Resilience Act that means an early warning within 24 hours of learning of an actively exploited vulnerability or a severe incident, a notification within 72 hours, and a final report within 14 days for a vulnerability or one month for an incident.

What we do not promise

Not every report ends in a fix. Some describe risks we have decided to accept. When that is our answer, we say so and explain why, rather than closing the thread quietly.

This policy describes how we work. It is not a certification, and no outside body has assessed it.

Machine-readable contact

Our security contact is also published at /.well-known/security.txt, in the RFC 9116 format.

Changes to this policy

This policy is versioned. A material change gets a new version number and a date on this page. Current version: 1.0, effective 21 September 2026.