Trust Center
Vulnerability disclosure policy
We welcome reports from security researchers, customers and anyone else who finds a weakness in CIP Sentry or this website.
Last updated: September 30, 2026
How to report
Email security@cipsentry.com with:
- the affected product and version (or the web page URL),
- a description of the vulnerability and its potential impact,
- steps to reproduce, and any proof-of-concept code or screenshots,
- how you would like to be credited, if at all.
If the details are sensitive, ask us for an encrypted channel in your first message. Please don't include personal data or BES Cyber System Information belonging to any utility.
What we commit to
- We acknowledge your report within 3 business days.
- We give you an initial assessment within 10 business days and keep you informed as we work on a fix.
- We aim to fix confirmed critical and high severity issues within 30 days, and others within 90 days, and will tell you if we need longer.
- We notify affected customers through their designated security contacts with severity, affected versions, fixes and workarounds, as part of our CIP-013 commitments.
- We credit researchers in the advisory if they wish.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorized, we will work with you to understand and resolve the issue quickly, and we will not recommend or pursue legal action related to your research.
Guidelines
- Test only against your own installation of CIP Sentry or this public website. Never test against a utility's production system.
- Do not access, modify or delete data that isn't yours, and stop as soon as you have demonstrated the issue.
- Do not perform denial of service, social engineering, physical attacks or spam.
- Give us a reasonable time to fix the issue before any public disclosure. We will agree a coordinated disclosure date with you.
Scope
In scope: the CIP Sentry application (web app, API, desktop app, updater and installers) and this website. Out of scope: third-party services we don't operate, and findings that require a compromised customer server or physical access.
Machine-readable contact details are published in our security.txt file (RFC 9116).

