Vulnerability Disclosure Policy

At Fox ESS, we take the security of our products, cloud platform, and mobile applications extremely seriously.

We are committed to working with the security community, customers, installers, and partners to identify and resolve potential vulnerabilities responsibly.

This page explains how to report vulnerabilities to us and what you can expect in return.

Scope

This policy covers all products and services provided by Fox ESS, including:

  • Solar inverters, battery storage systems, and communication modules

  • Fox Cloud backend services

  • Fox ESS mobile applications

  • APIs, web services, and device firmware

How to Report a Vulnerability

If you believe you have discovered a security vulnerability in a Fox ESS product or service, please let us know as soon as possible.

Email: security@fox-ess.uk

When reporting, please include:

  • A clear description of the issue

  • Steps to reproduce

  • Product model, firmware version, or platform affected

  • Any supporting evidence (logs, screenshots, payloads etc.)

  • Your contact details (optional if you prefer anonymity)

If you need to share sensitive information, we encourage using encrypted communication.

What to Expect

 

Acknowledgement

We will acknowledge your report within 5 working days.

Investigation

Our security and engineering teams will analyse the report and may contact you for further details.

Remediation

Validated vulnerabilities will be prioritised and resolved as quickly as possible.
Critical security issues receive immediate attention.

Coordinated Disclosure

We request that researchers allow up to 90 days before publicly disclosing a vulnerability, giving us time to develop and release fixes.
We will communicate timelines and progress updates throughout the process.

Guidelines for Responsible Disclosure

To protect users and systems, we ask that researchers:

Do

  • Report vulnerabilities promptly

  • Act in good faith and avoid causing harm or disruption

  • Test only on systems you own or have permission to work with

  • Respect the privacy and data of others

  • Allow us reasonable time to remediate the issue

Do Not

  • Access or modify data belonging to others

  • Perform denial-of-service attacks

  • Conduct social engineering or phishing

  • Exploit or weaponise a vulnerability

  • Break the law in the process of testing

Researchers acting responsibly under this policy will not face legal action from Fox ESS.

Security Update Support

Fox ESS provides security updates for the full supported lifecycle of each product, up to the published end-of-life (EOL) date.

Critical patches may be issued beyond EOL where necessary and technically feasible.

Contact

Fox ESS Security Team
Email: security@fox-ess.uk
Address: Fox ESS UK Ltd, Unit C1 Loades Ecoparc, Coventry CV7 9FW

Policy Versioning

  • Version: 1.0

  • Published: February 2025

  • Next Review: February 2026