Product Security

At Kempower, product security is built in end to end, from charger firmware to the ChargEye cloud. Guided by recognised industry standards, we continuously monitor, test, and improve our solutions to keep your charging infrastructure resilient and trustworthy.

Product Security at Kempower

Kempower is committed to the security of its products and services. On this page you can find information related to Kempower product security.

•Public CVD policy

•Report a vulnerability

•Security contact

•Security advisories

Kempower service team working

Built in end-to-end

Kempower is committed to the security of its products and services. We value the work of the security research community and welcome reports of potential security vulnerabilities in our products.

Public CVD Policy

Certified security with ChargEye – read more in a White paper.

  • Kempower’s Product Security Incident Response Team (PSIRT) is the dedicated team responsible for keeping our products and customers secure. We monitor for vulnerabilities across our EV charging hardware, firmware, and ChargEye cloud services, and coordinate their investigation, remediation, and disclosure across each product’s entire lifecycle. Working closely with security researchers, national authorities, and our product teams, the PSIRT ensures that reported issues are handled responsibly, transparently, and resolved as quickly as possible.
    Report a vulnerability

Future security vulnerability advisories will be listed here.

For security reports in general and additional guidance, you can contact us at: security@kempower.com



Kempower Coordinated Vulnerability Disclosure Policy

Kempower is committed to the security of its products and services. We value the work of thesecurity research community and welcome reports of potential security vulnerabilities in ourproducts.

This policy applies to all Kempower connectable products, including:

  • Kempower charging systems
  • Kempower cloud services
  • Kempower mobile applications

Reporting a Vulnerability

Contact

Report findings using the form at www.kempower.com/product-security. We accept reports in English or Finnish. We will handle vulnerability reports confidentially and use reporter contact information solely for vulnerability management purposes.

For general product support inquiries, please use support@kempower.com. 

Anonymous Reporting

You may report vulnerabilities anonymously. In order to receive feedback from us a valid emailaddress needs to be provided.

Additionally you may submit reports through the national CSIRT. In Finland, contact NCSC-FI(Traficom): Report an information security incident

What to Expect After Reporting

We will acknowledge receipt of your report provided that valid contact information was providedupon submission of the report.

We will provide an initial assessment confirming whether we can reproduce the issue and ourpreliminary severity evaluation.

We will provide updates during the remediation process until the vulnerability is consideredresolved even if Kempower considers the vulnerability not to be applicable to Kempowerproducts.

We aim to remediate confirmed vulnerabilities and release a security update without undue delay. The remediation timeline depends on the severity and complexity of the vulnerability. We request coordinated disclosure and will work with the reporter to agree an appropriate disclosure timeline.

Kempower will not pursue legal action against individuals who:

  • Report vulnerabilities in good faith and in compliance with this policy
  • Do not access, modify, or delete data beyond what is necessary to demonstrate thevulnerability
  • Do not exploit the vulnerability beyond what is needed to confirm its existence
  • Do not perform denial-of-service attacks, social engineering, or physical attacks
  • Do not target systems of Kempower customers or end-users

We consider security research conducted in accordance with this policy to be authorizedactivity. We will work with you to understand and resolve reported issues.