K2K/Charging
Legal · Security

Security

Charging infrastructure is critical infrastructure. We take security seriously — in our hardware, our software, our data practices, and our response to vulnerabilities.

Last updated: 27 May 2026

Our security posture

K2K Power takes the security of its charging infrastructure and management platform seriously. The practices described on this page reflect how we operate. Formal certifications are listed only where a current certificate can be produced on request.
  • All data in transit is encrypted with TLS 1.3 minimum. TLS 1.0 and 1.1 are disabled.
  • All data at rest is encrypted using AES-256 on AWS managed keys (AWS KMS).
  • OCPP connections use WSS (WebSocket Secure) with mutual TLS for DC fast chargers.
  • Payment data is tokenised — we never store full card numbers or UPI IDs.
  • API authentication uses OAuth 2.0 with short-lived (1-hour) access tokens and rotating refresh tokens.
  • CSMS sessions use signed JWTs with 15-minute expiry and refresh rotation.
  • All infrastructure is deployed in AWS ap-south-1 (Mumbai) with multi-AZ redundancy.

Application security

  • CSMS dashboard and rider app undergo OWASP Top 10 review on every major release.
  • Dependency scanning on all repositories, with critical advisories prioritised for patching.
  • Static analysis (SAST) integrated into CI/CD pipeline — builds fail on critical findings.
  • Dynamic application security testing (DAST) run quarterly by our internal AppSec team.
  • Secrets are managed via AWS Secrets Manager — no credentials in source code or environment files.
  • All production deployments require two-person review (4-eyes rule) and are approved by a senior engineer.
  • RBAC is enforced at every API layer — operators cannot access other operators' data; vendors cannot access other vendors' data.

Hardware security

  • Charger firmware is signed with K2K's private key. Unsigned firmware cannot be installed via OTA or physical interface.
  • Secure boot is enabled on K2K charger controllers.
  • OCPP passwords are unique per charger, rotated on commissioning and every 6 months.
  • Physical tamper detection alerts the CSMS and disables the unit until a field engineer clears the alert.
  • USB and debug ports on the charger controller are disabled in production firmware.
  • SIM cards are locked to K2K's CSMS endpoint — they cannot be redirected to a third-party server.

Operational security

  • All staff complete security awareness training quarterly.
  • Production access requires hardware MFA (YubiKey). Shared credentials are not permitted.
  • Database access by engineers requires a just-in-time (JIT) approval workflow — no standing production access.
  • All admin actions in CSMS are logged to an immutable audit trail (AWS CloudTrail + S3 Object Lock).
  • Security incidents are classified P1–P4, with data breach or service compromise treated as the highest priority.
  • We maintain an incident response plan and review it periodically.

Responsible disclosure

We welcome security researchers. If you discover a vulnerability in any K2K service or hardware, please disclose it responsibly and we will acknowledge, investigate, and fix it.

To report a vulnerability:

  • Email support@k2konline.in with details of the vulnerability, steps to reproduce, and your assessment of severity.
  • Include enough detail for us to reproduce the issue. We will confirm receipt and keep you updated on our assessment.
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it.
  • Do not access, modify or destroy data belonging to other users.
  • Give us a reasonable time to investigate and fix before public disclosure. We will confirm receipt and keep you updated on progress.

We do not pursue legal action against researchers who act in good faith under this policy. We acknowledge all valid reports and credit researchers (with consent) in our Hall of Thanks.

Bug bounty

SeverityCVSS rangeReward
Critical9.0 – 10.0Acknowledged case by case
High7.0 – 8.9Acknowledged case by case
Medium4.0 – 6.9Acknowledged case by case
Low0.1 – 3.9Acknowledged case by case
InformationalAcknowledgement

Scope includes: k2konline.in, the K2K CSMS dashboard, the K2K app, and K2K charger firmware (physical access required for hardware reports).

Out of scope: social engineering, physical attacks on chargers in the field, denial-of-service attacks, and spam.

Security contact

For general security questions or to report a vulnerability:

Security team: support@k2konline.in
Emergency (active breach): support@k2konline.in