Security Policy for Netzero
Last Updated: September 28, 2026
1. Introduction
Netzero Labs, Inc. is committed to ensuring the security and privacy of its users when interacting with the Netzero app. This security policy outlines the measures implemented to safeguard user data and maintain the integrity of the application. How we collect and use data is described in the Privacy Policy.
2. Access Control
Sign-in: you sign in to Netzero through Tesla's own sign-in page using OAuth. Netzero never sees or stores your Tesla password. Netzero only receives API tokens generated by Tesla, limited to the permissions you approve on Tesla's consent screen.
Least Privilege: the Netzero app only requests permissions necessary for its functionality. From Tesla, it requests access to your profile, energy device data and commands, and, optionally, vehicle data and charging commands. It does not request vehicle location. Other integrations, such as Enode and energy supplier accounts, are limited to the data and controls their features need.
Local Powerwall access: when you connect the app to your Powerwall on your local network, the gateway Wi-Fi password and login stay on your device and are never sent to Netzero.
Signed commands: commands to Tesla vehicles are signed with Netzero's key using Tesla's vehicle command protocol, and only work on vehicles where you have added Netzero's virtual key. When you pair Netzero with your Powerwall, a key unique to your system is registered on the gateway so that commands can be verified. You can remove the virtual key or pairing at any time.
Staff Access: access to production systems is limited to a small number of authorized staff and requires multi-factor authentication. Staff access user data only as needed to operate the service, investigate issues, and respond to support requests.
3. Data Encryption
In Transit: the Netzero app and websites connect to Netzero over HTTPS with TLS 1.2 or later, and our websites use HTTP Strict Transport Security (HSTS). Connections from our servers to our databases and caches are also encrypted.
At Rest: Netzero's databases, file storage, caches, and server disks are encrypted at rest. API tokens obtained from Tesla and other service providers are stored in these encrypted databases. Off-site database backups are additionally encrypted before they leave our infrastructure. Netzero's own signing keys and service credentials are kept in a dedicated secrets manager.
On Your Device: API tokens stored by the app use platform-specific mechanisms:
- iOS: stored in the Keychain, encrypted using iOS encryption standards.
- Android: stored in encrypted storage, encrypted using Android encryption standards.
- Web: stored in the browser's local storage. Sign out when using a shared computer.
4. Infrastructure Security
- Netzero runs on Amazon Web Services in the United States. Application servers, databases, and caches run in private networks and are not directly reachable from the internet.
- Firewall rules restrict each component to the connections it needs. Requests to our API are rate limited.
- We use automated threat detection, audit logging of infrastructure changes, and configuration monitoring, and we perform periodic security reviews of our infrastructure.
- Databases are backed up automatically, and encrypted off-site backups are stored with a separate cloud provider.
- We monitor our services for errors and outages, and apply security updates to our servers and dependencies.
5. API Security
APIs: Netzero utilizes APIs provided by Tesla and other service providers. These APIs adhere to industry-standard security practices and protocols.
Notifications from payment providers and integrations are verified before they are processed.
Developer API: developer API tokens can be revoked or regenerated at any time in the app. Treat your token like a password.
6. Revoking Access
- Tesla: you can revoke Netzero's access at any time in your Tesla account under third-party apps. After that, Netzero can no longer access your Tesla account data or send commands to your devices.
- Vehicles: you can remove Netzero's virtual key from your vehicle's Locks menu.
- Other integrations: you can disconnect Enode devices and energy supplier accounts in the app, or revoke the API keys with the provider.
- Account deletion: deleting your Netzero account removes your data as described in the Privacy Policy. It does not revoke access in your Tesla account, so revoke it there as well if you no longer use Netzero.
7. Incident Response
Incident Reporting: Users are encouraged to report any security incidents or concerns related to the Netzero app promptly to security@netzero.energy.
Response Protocol: In the event of a security incident, Netzero Labs, Inc. will promptly investigate, mitigate, and respond to the incident. If an incident affects your personal data, we will notify you and the relevant authorities as required by law.
8. Reporting Vulnerabilities
If you believe you have found a security vulnerability in Netzero, please report it to security@netzero.energy with enough detail for us to reproduce it. We ask that you:
- give us reasonable time to fix the issue before disclosing it publicly;
- only test against your own account and devices, and do not access, modify, or delete other users' data;
- do not perform denial-of-service testing, spam, or social engineering.
We will not take legal action against researchers who report vulnerabilities in good faith and follow these guidelines.
9. Conclusion
Netzero Labs, Inc. is dedicated to ensuring the security and privacy of its users' data. By adhering to stringent security measures, employing encryption protocols, and maintaining compliance with relevant regulations, Netzero Labs, Inc. strives to provide a safe and reliable experience for its users.
This security policy is subject to periodic review and updates to reflect evolving security requirements and best practices.