Coordinated Vulnerability Disclosure Policy
1. Overview
【Alpha ESS Co., Ltd.】 places a high priority on product cybersecurity and is committed to continuously improving the security capabilities of its products.
【Alpha ESS Co., Ltd.】 welcomes cybersecurity researchers, customers, partners, suppliers, and other relevant stakeholders to responsibly report potential security vulnerabilities identified in 【Alpha ESS Co., Ltd.】 products through a coordinated, responsible, and controlled disclosure process.
This policy describes the vulnerability reporting channels, required reporting information, communication mechanisms, vulnerability handling principles, and coordinated vulnerability disclosure practices established by 【Alpha ESS Co., Ltd.】. The objective is to ensure that potential cybersecurity risks affecting product security, data protection, system availability, and user operating environments are identified, assessed, and mitigated in a timely manner.
2. Scope of Application
This policy applies to 【Alpha ESS Co., Ltd.】 products that are within their supported lifecycle, including:
Software products;
Hardware products containing software components;
Digital products with network connectivity capabilities.
For products that have reached End-of-Life (EOL) or are no longer within the supported lifecycle, 【Alpha ESS Co., Ltd.】 may still accept vulnerability reports and will evaluate each case based on product status, potential user impact, and technical feasibility.
3. Vulnerability Reporting Channels
If you identify a potential cybersecurity vulnerability affecting a 【Alpha ESS Co., Ltd.】 product, please submit your report through the following channels:
Security Contact Email:
Security Website / Vulnerability Disclosure Page:
【Security Page URL】
If the report contains sensitive technical information, such as vulnerability details, Proof-of-Concept (PoC) code, log files, configuration files, cryptographic keys, or authentication-related information, encrypted communication is recommended.
4. Recommended Vulnerability Report Information
To facilitate efficient vulnerability analysis and handling, vulnerability reports should include, where available:
Reporter name, organization, and contact information;
Product name, model, software version, firmware version, and affected components;
Vulnerability description, affected scope, and potential security impact;
Vulnerability reproduction steps and test environment information;
PoC, screenshots, logs, or other supporting evidence.
If the provided information is insufficient for analysis, 【Alpha ESS Co., Ltd.】 may contact the reporter to request additional details.
5. Communication Process and Expectations
Upon receiving a vulnerability report, 【Alpha ESS Co., Ltd.】 will acknowledge receipt within a reasonable timeframe.
The acknowledgement may include:
Vulnerability tracking identifier;
Current processing status;
Follow-up communication method;
Requests for additional information.
During vulnerability verification, risk assessment, remediation activities, and security advisory preparation, 【Alpha ESS Co., Ltd.】 will maintain appropriate communication with the reporter based on the circumstances of the case.
6. Coordinated Disclosure Principles
【Alpha ESS Co., Ltd.】 follows the principles of Coordinated Vulnerability Disclosure (CVD) when handling product security vulnerabilities.
During vulnerability analysis and remediation activities, 【Alpha ESS Co., Ltd.】 will:
Maintain necessary communication with vulnerability reporters;
Avoid public disclosure of detailed information regarding unpatched vulnerabilities before appropriate remediation measures are available;
Determine a reasonable disclosure timeline based on vulnerability severity, exploitation risk, and remediation progress.
After remediation is completed, relevant information may be published through:
Official security advisories;
Product security notifications;
Customer security communications;
Security update announcements.
7. Reporter Code of Conduct
Security researchers and other reporters should:
Avoid performing unauthorized testing against production environments;
Avoid disrupting normal product operation;
Avoid accessing, modifying, or disclosing user data;
Avoid conducting denial-of-service attacks, malware injection, or other harmful activities;
Limit testing activities to the minimum scope required to verify the vulnerability;
Maintain confidentiality of vulnerability information before official disclosure.
8. Safe Harbor Statement
For security researchers and other parties who submit vulnerability reports in good faith, comply with this policy, and act with the objective of improving product security, 【Alpha ESS Co., Ltd.】 will handle such reports in a cooperative manner.
This statement does not apply to activities involving unauthorized access, illegal data acquisition, malicious attacks, disclosure of sensitive information, or actions that may impact customer business continuity.
9. Policy Updates
【Alpha ESS Co., Ltd.】 may update this policy based on regulatory requirements, product lifecycle changes, improvements to vulnerability management processes, and evolving cybersecurity requirements.
The latest version of this policy will be published on the official security page of 【Alpha ESS Co., Ltd.】.