Skip to main content

Security

Reporting a Vulnerability

If you discover a security vulnerability in EnergyIQ hardware or software, please report it responsibly to:

security@energyiq.com.au

We will acknowledge your report within 48 hours and provide a timeline for resolution. We request that you do not publicly disclose the vulnerability until we have had an opportunity to address it.

Software Update Policy

EnergyIQ hubs receive automatic security updates every night at 3am AEST/AEDT during a safe maintenance window. Updates are verified with Ed25519 cryptographic signatures before installation. Critical security patches are deployed as mandatory updates with an escalating urgency schedule.

Supported Versions

VersionSupport Level
CurrentFull support — features and security patches
PreviousSecurity patches only
OlderUnsupported

Security Features

  • Ed25519 signed updates — all firmware binaries are cryptographically signed and verified before installation
  • TLS-only communications — all hub-to-cloud communication uses HTTPS with TLS 1.2+
  • Local-first architecture — core functionality operates without internet connectivity, reducing attack surface
  • BLE ECDH encryption — device provisioning uses ephemeral ECDH key exchange with AES-256-GCM
  • Minimal open ports — only SSH and LAN API ports are open; firewall denies all other inbound traffic

Australian Compliance

EnergyIQ is designed to comply with the Cyber Security (Security Standards for Smart Devices) Rules 2025 (Australia). This includes automatic security update capabilities, unique device identifiers, a published security disclosure contact, and a defined software support period.