Coordinated Vulnerability
Disclosure Policy
Last Updated: August 28, 2026
01 Introduction and Commitment
At Inventus Power, Inc, we attach great importance to the security of our products and users. We are committed to providing secure products, including but not limited to our battery chargers, rechargeable battery packs, battery management systems, Internet of Things (IoT) devices, and related firmware/software.
We recognize that security vulnerabilities may be discovered during the lifecycle of a product (including its software and hardware components). To this end, we have established this Coordinated Vulnerability Disclosure Policy. We welcome and appreciate security researchers, industry partners, and users reporting potential security vulnerabilities to us in a responsible manner.
02 Scope
We encourage responsible reporting of vulnerabilities affecting the following products:
- Hardware products: All products subject to the EU Cyber Resilience Act (CRA), including but not limited to battery chargers, rechargeable battery packs, related control units, Internet of Things (IoT) devices.
- Embedded software/firmware: All embedded software/firmware subject to the CRA, including but not limited to MCU firmware, bootloaders, and communication protocol stacks.
The following are generally not within the scope of this policy:
- Denial of Service (DoS/DDoS) attacks.
- Social engineering attacks against our employees or customers (phishing, vishing, etc.).
- Physical attacks or tampering with devices.
- Issues that require physical access to the device and cannot be exploited remotely.
03 Vulnerability Reporting Guidelines
We provide the following methods for receiving vulnerability reports:
Contact Phone
+1.630.410.7900
[email protected]
Vulnerability information is extremely sensitive; we strongly recommend that all emails containing security vulnerability reports sent to us be encrypted using PGP/GPG keys.
To help us quickly verify and reproduce the issue, please include the following information in your report as much as possible:
- Product and version — affected specific device model, SN.
- Vulnerability description — a clear description of the potential vulnerability and its potential impact.
- Steps to reproduce — detailed, step-by-step instructions or proof-of-concept that allow us to reproduce the issue.
- Vulnerability impact — explain the possible impact of the vulnerability.
- Your contact information — your name, email address, or other communication methods.
Key fingerprint:
28681B11 B390E352 367546BF CD7703A0 AE37F2CB
04 Vulnerability Handling Procedure
We will conduct a preliminary screening immediately upon receiving the report to confirm whether it is a valid vulnerability report.
For valid vulnerability reports, we will send an acknowledgment receipt to the reporter within 2 business days, specifying the contact person, contact information, and subsequent handling process. We will maintain open and regular communication with the reporter throughout the investigation process, and promptly inform them of our progress in verifying, classifying, and remediating the vulnerability.
For invalid vulnerability reports, we will provide the reason for rejection and terminate the handling process. Invalid vulnerability reports include the following:
- The vulnerability cannot be reproduced, and no more valid information can be obtained.
- It is a duplicate report.
- The vulnerability exists in a product that has been discontinued and is no longer supported.
- The issue is not a security vulnerability or cannot be exploited at this time.
- Other invalid situations.
04 Vulnerability Handling Period Agreement
During the vulnerability receiving and acceptance stage, the confidentiality period will be evaluated and determined based on the vulnerability risk level, impact scope, and remediation difficulty:
|
RISK LEVEL |
CONFIDENTIALITY PERIOD |
|---|---|
|
High |
180 Days |
|
Medium |
120 Days |
|
Low |
60 Days |
- Please keep the discovered vulnerability information confidential during the confidentiality period.
- It is prohibited to cause potential or actual damage to the hardware or software systems of our company and users.
05 Disclaimer and Reserved Rights
The company reserves the right to judge and handle vulnerability reports at its own discretion, including deciding whether to fix, the time for vulnerability remediation, and the time for public disclosure, and reserves the right to modify this policy at any time.
If the reporter violates the obligations stipulated in this policy and commits any of the following acts, the company will immediately terminate communication with them and reserves the right to pursue civil, administrative, and criminal liability. If this causes losses to the company and its customers, the company will demand compensation according to law:
- Intentionally submitting false vulnerability information to interfere with the company’s normal security work;
- Reporting vulnerabilities not through the company’s official channels, or disclosing vulnerability details to third parties or the public before the company completes the fix;
- Using the reported vulnerability to carry out attacks, steal company and customer data, disrupt the normal operation of information systems, or other illegal acts;
- Disclosing internal sensitive information provided by the company during the vulnerability handling process;
- Using vulnerability reporting as an excuse to demand property from the company, make unreasonable requests, or use threats, coercion, or other means to interfere with the handling work;
- Violating other obligations of this policy and refusing to rectify after being reminded by the company.