Vesync Security
Coordinated Vulnerability Disclosure Policy
Scope: VeSync consumer IoT small appliances, mobile applications, cloud services, firmware, supporting APIs, and third-party software components integrated therein.
1. Our Commitment
VeSync values product and user data security, and welcomes good-faith reports of security vulnerabilities that may affect our products or services from any individual or organization. We will confirm, assess, remediate, and disclose vulnerabilities in a responsible manner, and where applicable, provide clear and accessible remediation guidance to affected users.
2. How to Report a Vulnerability
Please report to us through the following single point of contact (SPOC):
- Security email: datasecurity@vesync.com
- PGP public key: VeSync Security PGP Key
We support reporters using their preferred communication method and do not limit reporting channels to automated tools. We accept anonymous reports; if you require assistance from a coordinating body, coordinated disclosure may be conducted through the CSIRT/CERT designated by EU Member States.
We operate a bug bounty program. For specific scope and terms, please refer to the Bug Bounty Program page. Eligible reports may receive a reward.
If you have mistakenly sent sensitive information through a non-secure channel, please contact the security email above immediately.
3. Information to Include in Your Report
To help us process your report quickly, please provide as much of the following as possible:
- Affected product or service information, including product name, model, and version information (where applicable);
- Vulnerability description and potential impact;
- Reproduction steps, proof of concept (PoC), logs, or screenshots;
- Your suggested fix or mitigation measures;
Please do not provide unnecessary personal data, real user credentials, or data from other users.
4. Response & Handling
- Report receipt: Acknowledged within 2 business days
- Status updates: Progress updates every 2–3 weeks until the vulnerability is remediated
The above are service targets and do not constitute a guarantee of a fixed remediation period for all vulnerabilities; actual timelines depend on vulnerability severity, exploitability, number of affected devices, supply chain dependencies, and user security risk.
5. Coordinated Disclosure Principles & Security Advisories
Before a vulnerability fix or effective mitigation is available, reporters should refrain from publicizing technical details that could lead to exploitation of the vulnerability.
Where third-party components, upstream suppliers, or coordinating bodies are involved, we will coordinate with relevant parties within an appropriate scope to jointly advance vulnerability remediation and disclosure.
Once a fixed version or effective mitigation is available, we will publicly release appropriate information related to the remediated vulnerability, including:
- Vulnerability identifier (where applicable, e.g. CVE)
- Vulnerability description
- Vulnerability severity
- Affected products, versions, or services
- Fixed versions, mitigation measures, and user action guidance
- Initial publication date and last update date
- Reference links (where applicable)
If immediate disclosure would expose users to greater security risk, we will delay disclosure of technical details until users have installed patches or taken mitigation measures.
6. User Remediation & Security Updates
Within the product security support period, we will make available security updates in a timely manner.
7. Good-Faith Security Research
Subject to compliance with this policy, we will not initiate legal action against researchers for good-faith security research. Good-faith research includes:
- Testing only to the extent necessary;
- Avoiding impact on device availability, user privacy, or service continuity;
- Not exploiting vulnerabilities to obtain data, assets, or improper benefits;
- Not conducting social engineering, denial of service, extortion, physical destruction, or large-scale automated scanning;
- Not accessing, modifying, deleting, or disclosing other people's data;
- Giving us a reasonable opportunity for coordination and remediation before public disclosure.
This policy does not authorize you to bypass laws, contractual obligations, or access controls of third-party systems.
8. Privacy & Information Handling
We process reporter information only for the purposes necessary to receive, verify, remediate, and disclose vulnerabilities, and handle personal data in accordance with applicable data protection laws. We will not disclose the identity of a reporter unless required for remediation, coordinated disclosure, fulfillment of legal obligations, or with your consent.