Product cybersecurity

Report a suspected cybersecurity vulnerability in an XP Power product.

We welcome reports from customers, security researchers and suppliers.

Report a vulnerability

Anything marked with an asterisk is required. Everything else helps us assess the issue faster, but leave it blank if you are unsure or cannot share it safely.

The vulnerability

If known—for example a firmware revision or date code.

Please include only information that is lawful and safe for you to share.

Optional. Logs, screenshots or packet captures. Maximum 10 MB.

About you - optional

You can report anonymously, and we would rather have an anonymous report than no report at all. But please know what it costs: without a way to reach you we cannot ask follow-up questions, send you a case reference, or tell you when the issue is resolved. An anonymous report can only be investigated to a limited extent, and in some cases may not be actionable at all. Complex issues in particular usually need further explanation or documentation before we can act on them.

A phone number on its own is enough—you do not have to give us an email address.

Confirm

If you would rather not confirm this, email psirt@xppower.com instead—we will still assess your report.

We use what you send only to investigate and resolve the report. Personal data is handled in line with our Privacy Policy. Please do not include anyone else's personal data unless it is essential to understanding the issue.

Urgent, or actively exploited?

The form above asks whether you believe the vulnerability is being actively exploited. Flagging it there is enough — we prioritise those reports immediately. If you would rather not use the form at all, email us with the same detail and put “active exploitation” in the subject line.

What we can and cannot act on

  • Vulnerabilities in XP Power products and the software or firmware that runs on them

  • Digital interfaces, communications features and update mechanisms

  • Anything affecting the confidentiality, integrity, availability or safe operation of a product’s digital functions

Out of scope

  • General product support, pricing, delivery or commercial enquiries

  • Denial-of-service testing, social engineering, phishing, spam or physical attacks

  • Accessing, changing, deleting or disclosing data that is not yours

  • Third-party systems XP Power does not operate or control

Useful to include

  • Product name, model, variant and version

  • How you found it and how to reproduce it

  • What an attacker could achieve

  • Any mitigation or workaround you have already identified

  • Whether you have shared it with anyone else

What happens next

Every report follows the same path.

Where you have given us a way to contact you, we will come back to you within four working days — from a member of the product security team, a person, not an automated reply — with a case reference and a named owner. We will give you a fuller assessment within ten working days.

That fuller assessment will tell you at least one of the following: that we confirm the vulnerability, that we do not and why, that we need specific further information from you, or that the investigation is taking longer, with a further update within ten working days.

Enquiries about progress are welcome at any time.

If you have not given us a way to reach you, we cannot do any of the above — but we will still review your report. See the note on anonymous reporting in the form above.

  • Where we can reach you, your report is logged and given a case reference and a named owner in our product security team

  • We confirm which products are affected, check for duplicates and make an initial severity assessment

  • Engineering, quality and compliance assess the real-world impact and the options for resolving it

  • If exploitation is suspected or the issue is severe, it is escalated immediately to our incident response team

  • We coordinate the fix, any customer advisory and — where appropriate — public disclosure

  • The full process is set out in our Coordinated Vulnerability Disclosure policy

Safe harbour

If you report a vulnerability to us in good faith and follow the guidance on this page and in our Coordinated Vulnerability Disclosure policy, XP Power will not pursue criminal charges against you and will not encourage or assist a prosecution brought by anyone else, except where we are required by law to do so. This does not apply where there is evidence that you acted with criminal intent.

We will treat your report as confidential to the extent the law allows. We will not pass your name or contact details to anyone outside XP Power — including law enforcement — without your consent, unless we are legally required to. The only other thing we may publish is information that has to be published in order to disclose the vulnerability itself. We will not ask you to sign a non-disclosure agreement as a condition of reporting to us.

Where you have given us a way to reach you, we will remain available as a point of contact throughout the disclosure process, not only at the start.

If you are sending us anything confidential, we would rather you sent it encrypted and digitally signed. Our OpenPGP keys and their fingerprints are published under “Other ways to reach us” below.

If you are unsure whether what you have found is in scope, report it anyway. We would rather assess it and tell you it is out of scope than never hear about it.

How we work together

Disclosure and our CRA position

We ask reporters to coordinate disclosure with us before making details public, so that customers are not left exposed while a fix is being prepared.

Our position statement explains what Regulation (EU) 2024/2847, the EU Cyber Resilience Act, requires of manufacturers, how it applies to our products, and what we are doing about it.

XP Power and the EU Cyber Resilience Act (PDF)

What XP Power will do

  • Review every report submitted through the routes on this page

  • Assess severity, affected products and customer impact

  • Come back to you if we need more detail, where you have given us a way to reach you

  • Take corrective or mitigating action based on risk and technical feasibility

  • Coordinate any customer advisory, update or public disclosure, as set out in our Coordinated Vulnerability Disclosure policy

  • Credit you for the find, if you would like us to

What we ask of you

  • Act in good faith and avoid harm to XP Power, our customers, users and third parties

  • Do not exploit a vulnerability further than needed to show that it exists

  • Do not disrupt systems, services or customer operations

  • Do not access, change or disclose data that is not yours

  • Keep the details confidential until we have coordinated disclosure with you

Other ways to reach us

The form above is the quickest route. If you would rather not use it, any of these reach the same team.

Vulnerabilities in XP Power products.
OpenPGP key · fingerprint:
E6EE 9A58 FFEC 7301 C625 B0CA 3280 4FE1 21DB 4DA7

Issues affecting XP Power’s own systems and websites, rather than our products.
OpenPGP key · fingerprint:
30EF 837B 6074 DABC D0EC F375 18DE 2678 E322 EE22

By telephone

Monday to Thursday, 08:00–17:30 UK time.
Friday, 08:00–15:00 UK time.

+44 (0)118 984 5515

Outside these hours please use the form or email.

Our machine-readable security contact details are published at /.well-known/security.txt. That file is signed; the key that signs it is published so you can verify it. It is not an encryption key — use the keys above to encrypt a report to us.

Signing key fingerprint: 293E A24D E9A2 3E43 8D20 888A 0E9C 5079 3666 9A89

Acknowledgements

We are grateful to the people who report vulnerabilities to us responsibly. Where a reporter asks to be credited, we will name them here once the issue has been resolved and disclosure has been coordinated. We have no entries yet.

Issues resolved

We have no reported issues yet