Product cybersecurity
Report a suspected cybersecurity vulnerability in an XP Power product.
We welcome reports from customers, security researchers and suppliers.
Report a vulnerability
Urgent, or actively exploited?
The form above asks whether you believe the vulnerability is being actively exploited. Flagging it there is enough — we prioritise those reports immediately. If you would rather not use the form at all, email us with the same detail and put “active exploitation” in the subject line.
What we can and cannot act on
In scope
Vulnerabilities in XP Power products and the software or firmware that runs on them
Digital interfaces, communications features and update mechanisms
Anything affecting the confidentiality, integrity, availability or safe operation of a product’s digital functions
Out of scope
General product support, pricing, delivery or commercial enquiries
Denial-of-service testing, social engineering, phishing, spam or physical attacks
Accessing, changing, deleting or disclosing data that is not yours
Third-party systems XP Power does not operate or control
Useful to include
Product name, model, variant and version
How you found it and how to reproduce it
What an attacker could achieve
Any mitigation or workaround you have already identified
Whether you have shared it with anyone else
What happens next
Every report follows the same path.
Where you have given us a way to contact you, we will come back to you within four working days — from a member of the product security team, a person, not an automated reply — with a case reference and a named owner. We will give you a fuller assessment within ten working days.
That fuller assessment will tell you at least one of the following: that we confirm the vulnerability, that we do not and why, that we need specific further information from you, or that the investigation is taking longer, with a further update within ten working days.
Enquiries about progress are welcome at any time.
If you have not given us a way to reach you, we cannot do any of the above — but we will still review your report. See the note on anonymous reporting in the form above.
Where we can reach you, your report is logged and given a case reference and a named owner in our product security team
We confirm which products are affected, check for duplicates and make an initial severity assessment
Engineering, quality and compliance assess the real-world impact and the options for resolving it
If exploitation is suspected or the issue is severe, it is escalated immediately to our incident response team
We coordinate the fix, any customer advisory and — where appropriate — public disclosure
The full process is set out in our Coordinated Vulnerability Disclosure policy
Safe harbour
If you report a vulnerability to us in good faith and follow the guidance on this page and in our Coordinated Vulnerability Disclosure policy, XP Power will not pursue criminal charges against you and will not encourage or assist a prosecution brought by anyone else, except where we are required by law to do so. This does not apply where there is evidence that you acted with criminal intent.
We will treat your report as confidential to the extent the law allows. We will not pass your name or contact details to anyone outside XP Power — including law enforcement — without your consent, unless we are legally required to. The only other thing we may publish is information that has to be published in order to disclose the vulnerability itself. We will not ask you to sign a non-disclosure agreement as a condition of reporting to us.
Where you have given us a way to reach you, we will remain available as a point of contact throughout the disclosure process, not only at the start.
If you are sending us anything confidential, we would rather you sent it encrypted and digitally signed. Our OpenPGP keys and their fingerprints are published under “Other ways to reach us” below.
If you are unsure whether what you have found is in scope, report it anyway. We would rather assess it and tell you it is out of scope than never hear about it.
How we work together
Disclosure and our CRA position
We ask reporters to coordinate disclosure with us before making details public, so that customers are not left exposed while a fix is being prepared.
Our position statement explains what Regulation (EU) 2024/2847, the EU Cyber Resilience Act, requires of manufacturers, how it applies to our products, and what we are doing about it.
What XP Power will do
Review every report submitted through the routes on this page
Assess severity, affected products and customer impact
Come back to you if we need more detail, where you have given us a way to reach you
Take corrective or mitigating action based on risk and technical feasibility
Coordinate any customer advisory, update or public disclosure, as set out in our Coordinated Vulnerability Disclosure policy
Credit you for the find, if you would like us to
What we ask of you
Act in good faith and avoid harm to XP Power, our customers, users and third parties
Do not exploit a vulnerability further than needed to show that it exists
Do not disrupt systems, services or customer operations
Do not access, change or disclose data that is not yours
Keep the details confidential until we have coordinated disclosure with you
Other ways to reach us
The form above is the quickest route. If you would rather not use it, any of these reach the same team.
Product vulnerabilities
Vulnerabilities in XP Power products.
OpenPGP key · fingerprint:
E6EE 9A58 FFEC 7301 C625 B0CA 3280 4FE1 21DB 4DA7
XP Power IT infrastructure
Issues affecting XP Power’s own systems and websites, rather than our products.
OpenPGP key · fingerprint:
30EF 837B 6074 DABC D0EC F375 18DE 2678 E322 EE22
By telephone
Monday to Thursday, 08:00–17:30 UK time.
Friday, 08:00–15:00 UK time.
+44 (0)118 984 5515
Outside these hours please use the form or email.
Our machine-readable security contact details are published at /.well-known/security.txt. That file is signed; the key that signs it is published so you can verify it. It is not an encryption key — use the keys above to encrypt a report to us.
Signing key fingerprint: 293E A24D E9A2 3E43 8D20 888A 0E9C 5079 3666 9A89
Acknowledgements
We are grateful to the people who report vulnerabilities to us responsibly. Where a reporter asks to be credited, we will name them here once the issue has been resolved and disclosure has been coordinated. We have no entries yet.
Issues resolved
We have no reported issues yet