Vulnerability Response Process

 

 

1. Purpose 

This process defines our commitment to receiving, investigating, and disclosing security vulnerabilities in our products in a coordinated and responsible manner. We encourage security researchers and customers to report potential vulnerabilities to us so that we can address them before they are publicly disclosed.

This process supports and is implemented consistently with the Product Vulnerability Handling Process. Vulnerability reports received under this process shall be handled through the company’s controlled vulnerability handling process, including receipt, verification, remediation, release and post-release activities.

 

2. Scope

This process applies to all products with digital elements developed or maintained by ROYPOW Technology Co., Ltd..

 

3. Contact Mechanisms

We provide one channel for reporting security vulnerabilities. All reports should be sent to the following contact:

Channel Contact Information
Email psirt@roypow.com
PGP Key Click here to download

Key ID:DC0E2468
PGP fingerprint:CA79 93A7 8C98 3575 F6E9 4046 76ED 703E DC0E 2468

 

4. What to Report

When reporting a vulnerability, please include the following information as much as possible:

  • Product name and version 
  • Description of the vulnerability 
  • Steps to reproduce (PoC) 
  • Impact assessment 
  • Proposed mitigation (if any)
  • Your contact information (for follow-up) 

 

Anonymous Reporting:

We accept anonymous vulnerability reports. You may use a pseudonym or submit reports via our web form without providing identifying information. However, please note that without contact information, we cannot provide status updates or recognition.

 

5. Our Commitment

Upon receiving a vulnerability report, we commit to:

  • Acknowledgement: Confirm receipt within 3 working days.
  • Response: Review the report and provide feedback, request additional information, or communicate next steps within a reasonable timeframe.
  • Status updates: Maintain communication with the reporter and provide progress updates during the handling process, as appropriate to the nature and complexity of the reported vulnerability.
  • Disclosure: Coordinate the intended public disclosure with involved parties.
  • Recognition: Acknowledge the reporter’s contribution with permission.

Where these time frames cannot reasonably be met, we will inform the reporter of the reason and provide the expected next update date.

 

Vulnerability Severity Rating

We assess the severity of suspected vulnerabilities in our products based on industry standards, such as the Common Vulnerability Scoring System (CVSS). CVSS consists of four metric groups: Base, Threat, Environmental, and Supplemental. We encourage end users to assess the Environmental score based on their specific network conditions. This score serves as the final vulnerability score for the specific environment and supports decision-making on vulnerability mitigation and deployment.

We use Security Severity Rating (SSR) as a simplified approach to vulnerability classification. Under SSR, vulnerabilities are classified as critical, high, medium, low, or informational based on their overall severity scores.

 

6. Embargo Period and Disclosure Strategy

To protect our users, we request that you refrain from publicly disclosing the vulnerability until we have provided a fix or mitigation. We will agree on an embargo period with you based on the severity of the vulnerability and the complexity of the fix.

We follow the coordinated disclosure principle:

  • Privately notify reporters upon fix availability.
  • Publish security advisory after users have had reasonable time to apply the fix.
  • Public disclosure will normally occur after the agreed embargo period ends and appropriate remediation or mitigation is available. The disclosure timing or embargo period may be reviewed and adjusted where active exploitation is identified, vulnerability information becomes public, risk materially changes, remediation is delayed or becomes available earlier, or applicable legal or regulatory requirements require earlier action.

 

Publication and Remediation Distribution

Security advisories will be published through the company’s designated public security advisory or product support webpage.

Available security updates, corrected versions, patches or mitigation instructions will be distributed through the applicable product update service, product support or download portal, customer support channel, or another approved secure distribution channel. The advisory will identify the affected products and versions, available remediation or mitigation, required user actions and applicable support contact.

 

7. Secure Communication

For sensitive vulnerability information, we strongly recommend using PGP encryption when sending reports to psirt@roypow.com. Our PGP public key is available for download on our website.

Non-public vulnerability information will be shared only where necessary for vulnerability verification, remediation, mitigation, protection of affected users, coordination with relevant suppliers or maintainers, coordinated disclosure, or compliance with applicable legal and regulatory obligations.

Information will be limited to what the recipient needs for the relevant purpose and shared through an appropriate controlled channel. Where appropriate, the recipient will be informed of applicable confidentiality and embargo conditions. Personal information of the reporter will not be shared without consent unless required by law.

 

8. Scope and Limitations 

The following activities are outside the scope of this process:

  • Denial of Service (DoS) testing on production systems 
  • Physical attacks on facilities 
  • Social engineering attempts 
  • Testing that violates applicable laws 

 

9. Legal Safe Harbor 

We will not pursue legal action against individuals who submit vulnerability reports in good faith and in compliance with this process. We will not share your personal information with third parties without your consent, except as required by law.

We authorize good-faith, non-malicious security testing of products and systems within the scope of this process, provided that the testing complies with this process, applicable law and the restrictions below. Testing shall avoid harm to users, disruption of services, unauthorized access to or modification of data, privacy violations, and access beyond what is necessary to demonstrate the vulnerability.
Where testing is conducted in accordance with this process, we will consider the activity authorized for the purpose of vulnerability research and will not initiate legal action solely based on that activity. This authorization does not apply to testing outside the defined scope or to activities prohibited by this process.

 

10. Recognition 

We value the contributions of security researchers who help us improve product security. With your permission, we will acknowledge you in our security advisories.

 

11. Process Review

This process is reviewed annually or after significant security incidents. The latest version is always available on our website.

 

12. Contact

For questions about this process, please contact:

Channel Contact Information
Email psirt@roypow.com
PGP Key Click here to download

Key ID:DC0E2468
PGP fingerprint:CA79 93A7 8C98 3575 F6E9 4046 76ED 703E DC0E 2468

 

 

 
  • ROYPOW linkedin
  • ROYPOW youtube
  • ROYPOW tiktok
  • ROYPOW facebook
  • ROYPOW instagram
  • ROYPOW twitter

Subscribe to our newsletter

Get the latest ROYPOW's progress, insights and activities on renewable energy solutions.

Full Name*
Country/Region*
ZIP Code
Phone
Message*
Please fill in the required fields.

Tips: For after-sales inquiry please submit your information here.

Start Your FREE Subscription Today!
Get the latest ROYPOW's progress, insights and activities on renewable energy solutions.
Home ChatNow Pre-sales
Inquiry
After-sales
Inquiry
Become
a Dealer