At Senergy, security is a baseline requirement for how we design, build, and operate our products and services. We welcome responsible reports from researchers, customers, and partners about security issues that may affect our products, software, services, or related digital elements.

We follow Coordinated Vulnerability Disclosure (CVD). In general, we ask reporters to avoid public disclosure until a fix is available and coordinated publication is complete, unless otherwise agreed in writing.

We maintain a coordinated vulnerability disclosure process to support the secure, timely, and responsible handling of vulnerability reports affecting our products, software, services, or related digital elements.

Handling Approach

  • Provide publicly accessible reporting channels and acknowledge receipt within the stated timeframe;
  • Triage and assess reports and request additional details when needed;
  • Maintain appropriate communication with the reporter and affected stakeholders during handling;
  • Protect non-public vulnerability information as appropriate; and
  • Publish advisories and remediation guidance for resolved issues where applicable.

Our Commitments

  • Accessible Reporting Channels
    We provide publicly available reporting channels for researchers, customers, and partners.
  • Professional Triage
    We review incoming reports, request additional details where needed, and route cases through our internal tracking process.
  • Ongoing Communication
    We aim to provide acknowledgment, follow-up, and coordinated disclosure based on risk and remediation readiness.

Our Procedure for Responding to Vulnerability Information

01

RECEIVE

Receive and collect information on suspected product security vulnerabilities.

02

VERIFY

Coordinate with relevant teams to perform vulnerability validation and risk assessment.

03

REMEDIATION

Analyze the root cause of the vulnerability and implement vulnerability remediation.

04

DISCLOSE

Proactively disclose vulnerability information and release firmware updates/fixes.

According to EU Cyber Resilience Act (CRA) REGULATION (EU) 2024/2847

Actively exploited vulnerabilitySevere security incidents
Timeliness1. Early warning notification within 24 hours
2. General information submission within 72 hours
3. Final report no later than 14 days
1. Early warning notification within 24 hours
2. General information submission within 72 hours
3. Final report no later than 1 month
Content1. Vulnerability Description
2. Severity and Impact
3. Malicious Actors Exploiting the Vulnerability
4. Detailed Information on Security Updates or Corrective Measures
1. Incident Description
2. Severity and Impact
3. Threat Type or Root Cause
4. Mitigation Measures Taken and Ongoing

Last updated: [Month DD, YYYY]

Official Reporting Channels

For sensitive technical details, please use encrypted communication where possible.

  • PGP Public Key: /security/pgp-key.asc
  • Security Advisories: /security/advisories/
  • Safe Harbor: /security/safe-harbor/