Ecovacs Coordinated Vulnerability Disclosure (CVD) Policy

Version: V1.0
Latest Revision Date: August 10, 2026
  1. Introduction
We are committed to protecting the security of our products and the privacy of our users. We recognize that no product can be completely secure and that security researchers, customers, and members of the public play an important role in helping us identify and remediate security vulnerabilities.
This policy describes our commitment to product security and how we work with the security community through Coordinated Vulnerability Disclosure (CVD).
What is Coordinated Vulnerability Disclosure (CVD)?
Coordinated Vulnerability Disclosure is a process for responsibly handling security vulnerabilities through coordination among relevant stakeholders. The core principle of CVD is to avoid publicly disclosing detailed information about a vulnerability until a remediation is available and users have had a reasonable opportunity to apply the remediation. This approach helps maximize user protection while fostering trust and cooperation between security researchers and product manufacturers.
  1. Scope
This policy applies to all our products with digital elements and their associated services, covering our consumer and commercial service robot product portfolio, including, but not limited to:
  • Robot hardware and firmware
  • Mobile applications (APPs)
  • Cloud platforms and API services
  • OTA update platforms
  • Third-party components and open-source software
The following are outside the scope of this policy:
  • Theoretical vulnerabilities for which no actual exploitability or demonstrable security impact has been established;
  • Simple disclosure of non-sensitive information, such as version information;
  • Vulnerabilities affecting products that had reached End of Life (EOL) more than 12 months before the date of the report;
  • Vulnerabilities identified solely through automated scanning tools and not independently validated;
  • UI/UX defects or spelling errors that have no security impact;
  • Social engineering attacks and physical security testing.
Remediation Eligibility: products and services receive security fixes while they are within their defined support period. For example, a product is not eligible to receive remediation once it is beyond its published end-of-support date.
  1. Vulnerability Reporting Channels
If you discover a potential security vulnerability in one of our products, please report it to us through one of the following channels:
Channel Address Description
Security Email (Preferred) product-security@ecovacs.com Supports PGP-encrypted communication. The public key can be obtained from the address provided in this document.
Online Submission Form https://security.ecovacs.cn/en/submit-vulnerability Supports anonymous vulnerability reporting.

All electronic reporting channels use HTTPS/TLS encryption for data transmission. The security email supports PGP-encrypted communication. 
Accessibility: On the Product Security Center website, select “Screen Reader” from the accessibility menu to enable or disable screen reader assistance. Other accessibility options, such as contrast adjustment and link highlighting, are also available as needed.
  1. Safe Harbor
For external parties who conduct security research in good faith and in accordance with this policy, we commit to:
  • Treating their research activities as authorized;
  • Not initiating legal action or referring the matter to law enforcement solely because of their good-faith security research;
  • Cooperating in good faith to understand and remediate the reported vulnerability as efficiently as reasonably possible.
Good-faith security research should meet the following conditions:
  1. Interact only with systems that the researcher owns or is explicitly authorized to test;
  2. Avoid accessing or compromising user privacy, damaging data, or degrading the availability or performance of products or services;
  3. Access only the minimum amount of data necessary to demonstrate the vulnerability and do not retain, disclose, or misuse such data;
  4. Provide us with a reasonable opportunity to remediate the vulnerability before public disclosure;
  5. Do not use the research results for malicious purposes.
Exclusions: This Safe Harbor does not apply to activities including unauthorized access to internal networks, servers, or databases; intentional damage to products, services, or infrastructure; threats or harassment directed at employees or users; extortion; or intimidation.
  1. Report Content Requirements
To help us validate and remediate reported vulnerabilities efficiently, please provide the following information where available:
Information Description Required
Affected Product Product name, model, and firmware/APP/cloud version Yes
Vulnerability Description Description of the issue, triggering conditions, and vulnerability type Yes
Reproduction Steps Detailed step-by-step instructions for reproducing the vulnerability Yes
Impact Assessment Potential security impact if the vulnerability is exploited Yes
Proof of Concept (PoC) Technical demonstration sufficient to demonstrate the existence of the vulnerability (non-weaponized) Recommended
Discovery Information Date and method of discovery Recommended
Contact Information Name/alias and email address (may be omitted for anonymous reports) Recommended
  1. Our Commitments to Reporters
Upon receiving a vulnerability report, we will:
Stage Commitment Target Timeline
Acknowledgment Send an acknowledgment and assign a tracking number Within 3 calendar days
Initial Assessment Complete vulnerability validation and classification Within 14 calendar days
Progress Updates Provide the reporter with updates when there is material progress As progress is made
Remediation Completed Notify the reporter when remediation has been completed and, where appropriate, invite verification After remediation is completed
Coordinated Disclosure Coordinate with the reporter regarding the timing and content of public disclosure After the patch is released
Remediation Timeline:
  • Critical/High-severity vulnerabilities: Target remediation within 90 calendar days
  • Low-severity vulnerabilities: Target remediation within 180 calendar days
These timelines are targets rather than guarantees and may vary depending on the complexity, impact, affected products, and dependencies associated with a vulnerability.
  1. Coordinated Disclosure Principles
During the coordinated disclosure period, the following information should be treated as confidential:
  • Technical details of the vulnerability;
  • Proof-of-concept code and exploitation methods;
  • Affected product and version ranges;
  • Technical details of the remediation;
  • Unpublished security advisory drafts.
We ask reporters to provide us with a reasonable opportunity to investigate and remediate reported vulnerabilities before publicly disclosing them.
We will not publicly disclose detailed information about a reported vulnerability while remediation is in progress. Any public disclosure should, where reasonably practicable, be coordinated between the reporter and us.
Where appropriate, we may agree on a non-disclosure period during which detailed vulnerability information will not be publicly disclosed. The duration of the non-disclosure period may be adjusted on a case-by-case basis by mutual agreement, including where coordination with a coordinating party, third-party component provider, or other supplier is required.
  1. Public Disclosure

8.1 Security Advisory Content

Following the release of a security update, we will publish a security advisory on our official Security Announcement page. The advisory will include, at a minimum:
  • Vulnerability description;
  • Vulnerability identifier (CVE ID or vendor-assigned identifier);
  • Identification information for affected products;
  • Potential security impact of the vulnerability;
  • Vulnerability severity, including the CVSS score where applicable;
  • Remediation information;
  • Publication date and update date.

8.2 Publication Channels

Security vulnerability information may be published through the following channels:
  1. Acknowledgments
With the reporter's consent, we will acknowledge the reporter in the relevant security advisory.
The reporter may choose to:
  • Use their real name;
  • Use a pseudonym;
  • Remain anonymous.
  1. Policy Updates
This policy may be updated from time to time. The current version and its effective date are indicated at the beginning of this document.
Major changes are recorded below:
Version Date Changes
V1.0 August 10, 2026 Initial release
  1. Contact Information
Purpose Contact
Vulnerability Reports product-security@ecovacs.com
Policy Feedback product-security@ecovacs.com (Subject: “Policy Feedback”)
PGP Public Key https://security.ecovacs.cn/public-key.asc
Security Advisory Page https://security.ecovacs.cn/en/security-announcement
security.txt https://www.ecovacs.com/.well-known/security.txt