CEEC ENERGY STORAGE TECHNOLOGY (WUHAN) Co., Ltd. attaches great importance to security vulnerabilities associated with our products and services. To ensure customers can use our products and services with full confidence and facilitate the implementation of vulnerability remediation measures, we hereby formulate this Vulnerability Disclosure Policy. Guided by this policy, our company will make every effort to strengthen our security protection system.
This policy applies to energy storage battery container products sold and delivered by our company.
Our company has set up a dedicated vulnerability acceptance channel to receive vulnerability submissions from all parties. Upon receipt, we will acknowledge within 5 business days and provide weekly status updates to the reporter via email. If you discover any security vulnerabilities in our products or services, please contact us via the designated channels below:
After receiving a vulnerability report, our company will handle it in accordance with the following procedures:
The Product Design Department and Development Department will jointly conduct factual verification of all submitted vulnerability reports and send an acknowledgment of receipt within 5 working days. For coordinated disclosure scenarios, a confidentiality embargo period of up to 10 working days may be applied.
The Product Design Department and Development Department will jointly verify the reported information and classify vulnerabilities by severity based on the Common Vulnerability Scoring System (CVSS):
Our company undertakes to resolve reported vulnerabilities within the following timeframes:
The Company undertakes to disclose vulnerability resolution plans and remediation progress to relevant customers. Information disclosure recipients include vulnerability reporters and end users of affected products. The Company will prepare compliant disclosure documents and release relevant information to the public two weeks after the patch is delivered.
Our company will not initiate legal action against individuals who submit vulnerability information in good faith under this policy for the purpose of improving the security of our products, with respect to the following activities:
Customers who purchase our products are bound by contractual rights and obligations with our company. In addition, these products are not equipped with internet connectivity and can only be tested on-site. Relevant security testing may cause damage to in-operation or commissioned equipment.
If you intend to conduct testing on our equipment, you must submit an application to our company in advance through official cooperation channels or the listed contact methods. Only with prior written approval from our company, the following activities shall be eligible for safe harbor protection:
Our company will not pursue any legal liability against reporters who conduct activities within the above authorized scope.