Legal · v1.0 · Updated 2/13/2026
Responsible Disclosure Policy
Founding Partner Program Notice — This Platform is currently operated by an independent founder as part of its Founding Partner Program. Company registration details will be published here once the platform is incorporated. Until then, references to 'the Company' shall mean 'the Platform' operated by the Founder.
Scope
We welcome security researchers reporting vulnerabilities in EVChargeHub.com, the PWA, and our public APIs.
In-scope
- Authentication / authorization flaws
- Server-side injection (SQL, NoSQL, command)
- Sensitive data exposure
- Business-logic flaws
Out-of-scope
- DoS / DDoS
- Social engineering
- Reports based purely on outdated browsers
- Automated scanner output without a working PoC
Reporting
Email security@evchargehub.com (PGP available on request). Include steps to reproduce, impact assessment, and any PoC.
Rewards
Recognition in our Hall of Fame; monetary bounty at our discretion for high-impact reports.
Safe Harbour
Good-faith research that does not violate the Acceptable Use Policy will not be pursued legally.