This policy explains how PlugStream handles security updates, vulnerability reporting, and minimum security update periods for supported connected charge points.
Last updated: 3 May 2026.
PlugStream charge points are connected products. We design them to receive software and security updates through supported PlugStream services where the charger remains connected, installed correctly, and used within its supported configuration.
| Product family | Minimum security update period |
|---|---|
| PlugStream 7 | 5 years from first installation. |
| PlugStream 22 | 5 years from first installation. |
If your sales agreement, project contract, installer handover pack, or product statement gives a longer support period, that document takes priority.
The security update period is separate from the hardware warranty period. A security update period does not extend the warranty or create cover for faults, damage, misuse, or installation issues that are outside the warranty.
Security updates may include:
Updates may be delivered automatically or through a guided support process. Some updates require the charger to be online and able to communicate with PlugStream services.
To receive security updates, the charge point should:
If a charger is offline for a long period, removed, transferred, or reinstalled, contact PlugStream Support so we can advise on recommissioning and update status.
If you believe you have found a security issue, report it privately to PlugStream Support and include as much detail as possible. Please do not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and remediate it.
The Security Reporting policy explains our coordinated disclosure process.
Before a product family reaches the end of its minimum security update period, PlugStream will review whether support can continue. Where practical, we will provide customer or installer guidance before update support changes materially.