- Home
- Support
- Product Security
- Coordinated Vulnerability Disclosure (CVD) Policy
Coordinated Vulnerability Disclosure (CVD) Policy
We are committed to the security of our products and welcome responsible reports of security vulnerabilities from security researchers, customers, partners, and other members of the security community.
Reporting a Vulnerability
Please report potential vulnerabilities through our Product Security Vulnerability Reporting Form.
We accept reports in English and Chinese.
Please provide sufficient information to reproduce and assess the issue, including the affected product/version, vulnerability description, potential impact, reproduction steps, and relevant proof-of-concept or supporting evidence where available.
Our Commitments
For valid vulnerability reports, we will:
- Acknowledge receipt within 48 hours and provide a tracking ID.
- Notify the reporter of the assessed severity and estimated remediation timeline following triage.
- Provide status updates at least every 10 business days while the issue is being investigated or remediated.
- Work with the reporter toward coordinated disclosure, with a default disclosure target of 90 days from acknowledgement, subject to mutual agreement.
- Publish a security advisory, where appropriate, following remediation, including relevant vulnerability, affected-product, severity, and remediation information.
- Credit the reporter in the security advisory where the reporter has provided consent.
Safe Harbor
We support good-faith security research conducted in accordance with this policy and applicable law. We will not pursue legal action against researchers solely for authorized, responsible activities performed under this policy.
Researchers should:
- Test only systems, products, and environments they own or are authorized to test.
- Avoid intentionally causing damage, disruption, or loss of availability.
- Access personal data only when reasonably necessary to verify a vulnerability.
- Promptly notify us if personal data is inadvertently accessed and securely delete it.
- Not exploit vulnerabilities for malicious purposes, financial gain, or other unlawful activity.
- Avoid public disclosure before the agreed coordinated disclosure date.
This safe-harbor commitment does not apply to activities outside the scope of this policy or contrary to applicable law.
Scope
This policy applies to our products with digital elements, including products listed on our official website. Vulnerabilities in third-party or open-source components incorporated into our products may also be reported through this channel.
Regulatory and Standards Framework
This policy supports our vulnerability disclosure and handling processes with reference to the EU Cyber Resilience Act (Regulation (EU) 2024/2847) and ISO/IEC 29147:2018.
This policy does not limit or replace any mandatory legal or regulatory reporting obligations.
We may update this policy from time to time to reflect changes in our products, security practices, applicable laws, regulations, or industry standards.