Safe Harbor for Good-Faith
Security Research
We support good-faith security research intended to improve the security of our products and services. We value responsible engagement from the research community and will not initiate legal action against individuals who act in good faith and in accordance with this policy.
To qualify under this policy, researchers should
- Act in good faith and with the goal of improving security;
- Avoid privacy violations, service disruption, and data destruction;
- Refrain from social engineering, phishing, spam, or physical attacks;
- Use only the minimum steps reasonably necessary to demonstrate the issue;
- Promptly report the vulnerability through official channels; and
- Avoid public disclosure before remediation and coordinated publication, unless otherwise agreed.
Out of Scope Conduct
- Accessing, modifying, or deleting data that does not belong to you;
- Intentional service disruption or denial-of-service activity;
- Exploiting vulnerabilities beyond what is reasonably necessary to demonstrate the issue;
- Persistence, lateral movement, or privilege escalation in production systems;
- Physical attacks or hardware tampering unless explicitly authorized in writing; and
- Any activity that violates applicable law or regulation.
If you are unsure whether a planned research activity is appropriate, please contact us before proceeding at security@marstekenergy.com.