Reporting Suspected Vulnerabilities
If you encounter or find a suspected vulnerability in ROYPOW products, we would appreciate it if you could quickly inform our PSIRT. Please report suspected vulnerabilities through specified channels in accordance with the security mechanisms.
Vulnerability Reporting Channels
Please report suspected vulnerabilities using this template.
Please report suspected vulnerabilities in ROYPOW products via email, web form, or phone. ROYPOW PSIRT is ready to respond immediately to any suspected vulnerabilities reported by security researchers, industry organizations, customers, and suppliers.
| Channel | Contact Information |
| psirt@roypow.com | |
| PGP Key | Click here to download |
Key ID:DC0E2468
PGP fingerprint:CA79 93A7 8C98 3575 F6E9 4046 76ED 703E DC0E 2468
Anonymous Reporting:
We accept anonymous vulnerability reports. You may use a pseudonym or submit reports via our web form without providing identifying information. However, please note that without contact information, we cannot provide status updates or recognition.
Security Mechanism
Vulnerability information is sensitive. To ensure confidentiality, you are advised to encrypt the information sent to psirt@roypow.com using Pretty Good Privacy (PGP). You can click here to obtain ROYPOW's PGP public key (Key ID: DC0E2468; PGP fingerprint: CA79 93A7 8C98 3575 F6E9 4046 76ED 703E DC0E 2468).
Throughout the vulnerability handling process, ROYPOW PSIRT strictly ensures that vulnerability information is transferred only between relevant handlers. We sincerely request you to keep the information confidential until a complete solution is available to our customers.
Scope and Limitations
The following activities are outside the scope of this policy:
- Denial of Service (DoS) testing on production systems
- Physical attacks on facilities
- Social engineering attempts
- Testing that violates applicable laws
Publication and Remediation Distribution
Security advisories will be published through the company’s designated public security advisory or product support webpage.
Available security updates, corrected versions, patches or mitigation instructions will be distributed through the applicable product update service, product support or download portal, customer support channel, or another approved secure distribution channel. The advisory will identify the affected products and versions, available remediation or mitigation, required user actions and applicable support contact.















