Plugchoice
Security/Effective 9 July 2026

Responsible Disclosure

Version 2026-1, effective 9 July 2026

Applies to all systems of Volt Time B.V., trading as Plugchoice, including volttime.com, plugchoice.com, app.plugchoice.com, developer.plugchoice.com, ocpp.plugchoice.com, proxy.plugchoice.com, the mobile apps, the REST API, and all whitelabel or custom Partner domains through which the Plugchoice Platform is served, regardless of the branding shown.

If you discover a vulnerability, we want to know so we can fix it fast.

Please do

  • Email findings to security@plugchoice.com (see also /.well-known/security.txt).
  • Provide enough detail to reproduce (URL/endpoint, description, steps).
  • Give us reasonable time to fix before any disclosure.

Please do not

  • Exploit the finding beyond what is needed to demonstrate it; never access, modify or delete other people's data, and never send commands to chargers you do not own.
  • Use physical attacks, social engineering, DDoS, spam, or attacks on third-party services.
  • Reveal the problem to others before it is resolved.

Our promises

  • We aim to respond within 3 business days with our evaluation and an expected resolution date.
  • No legal action if you followed the rules above.
  • Strict confidentiality; your details are never shared without permission.
  • Progress updates, credit if you want it, and possibly a reward for previously unknown issues, at our discretion, sized to severity and report quality.