Vulnerability Disclosure Policy

Smart Power System Co., Ltd.

Smart Power System Co., Ltd. is committed to maintaining the security, integrity, and reliability of its products and services.

We welcome responsible vulnerability reports from customers, security researchers, partners, and related parties regarding potential cybersecurity issues affecting our products or services.

  1. Contact Information & Scope

This policy covers all equipment included in our company’s application plan and products. If you identify any security-related issues or potential vulnerabilities, please submit a report through the following channels:

  • Email: [email protected]
  • Website: https://www.spstaiwan.com.tw/jp/%E3%81%8A%E5%95%8F%E3%81%84%E5%90%88%E3%82%8F%E3%81%9B/
  1. Legal Notice & Research Guidelines

Smart Power System Co., Ltd. appreciates and welcomes good-faith, responsible, and legally conducted cybersecurity research and testing activities.

Without prior written authorization, performing any destructive testing that may impact product availability, customer operating environments, personal data, or normal service operations is strictly prohibited.

Smart Power System Co., Ltd. reserves the right of final interpretation, scope determination, and revision regarding this policy.

  1. Information Required in Report

When users, security researchers, or third parties encounter security-related issues, please submit a report through the designated channels mentioned above (website or email). To ensure a prompt and accurate follow-up investigation, please be sure to provide the following information when submitting your report:

  • Product Model and Equipment Information
  • Firmware or Software Version
  • Detailed Description of the Vulnerability
  • Reproduction Procedures or Test Conditions
  • Potential Impact and Risk Assessment (if known)
  • Proof-of-Concept Material (PoC code or screenshots, if available)
  • Reporter Contact Information (including name, email address, etc.)
  1. Vulnerability Handling Process

Upon receiving a cybersecurity vulnerability report, our company will manage and address all affected equipment in accordance with the following standard response process:

  • Acknowledgment & Contact Confirmation: Upon receiving a security issue report (in principle, within 5 business days), we will proactively contact the reporter via email to confirm the details of the report and vulnerability information.
  • Investigation & Verification: Our cybersecurity team will conduct technical testing or on-site investigations to verify the authenticity and exploitability of the reported issue.
  • Severity Classification & Assessment: For verified vulnerabilities, we will evaluate their potential impact, exploitability, and threat risks, and classify them based on severity levels.
  • Remediation & Mitigation Planning: We will formulate system enhancements, software/firmware patches, or temporary mitigation measures, and establish a specific repair timeline.
  • Notification to Affected Users: We will proactively inform affected users via email regarding the affected product models, vulnerability threat level (severity classification), and overall remediation plan.
  • Remediation Execution & Validation: Code fixes and internal security testing will be conducted to ensure the vulnerability is resolved without compromising system stability.
  • Completion Notification & Update Release: Upon completion of the repair, we will issue a follow-up notification via email and provide modified firmware or software updates through authorized maintenance procedures (including release notes or website announcements).
  1. Coordinated Disclosure Policy

Smart Power System Co., Ltd. practices the principle of Coordinated Vulnerability Disclosure (CVD). All cybersecurity vulnerability information will only be publicly disclosed after full verification, risk assessment, remediation planning, and corrective actions have been completed.

Disclosed information may include: affected product models, severity assessments, impact scope, mitigation recommendations, and maintenance update guidelines.

We kindly request that reporters refrain from disclosing vulnerability details to the public until remediation efforts are complete and affected customers have been appropriately informed.

  1. Firmware and Software Update Policy

All firmware and software updates must be performed by our company or authorized service personnel through “authorized and controlled standard maintenance procedures.”

Prior to installation, all update packages must undergo integrity and authenticity verification to ensure they have not been tampered with.

  1. Customer Notification

This Vulnerability Disclosure Policy is provided in full to customers who purchase our company’s products, either as an electronic document (such as PDF format) or through an official dedicated web page, ensuring that customers are clearly informed of the cybersecurity response and reporting mechanisms upon system delivery.