Rochenergy is committed to delivering safe, reliable and intelligent energy‑storage products and solutions for the global energy transition. We regard the cybersecurity of our products and services as a key responsibility. We welcome potential security‑vulnerability reports from users, security researchers and industry partners. Working together, we continuously improve product security and build a trustworthy energy future.
Report Security Vulnerabilities
Security is embedded into our product‑development workflows to protect customers and their connected environments.
We carefully review, assess and follow up on every vulnerability report.
We strive to acknowledge receipt of each vulnerability report within two working days.
We provide timely updates on processing progress and request supplementary information when necessary.
We address reported vulnerabilities for the duration of a product’s defined security‑support period.
Rochenergy values good‑faith security research. This policy describes how to report potential vulnerabilities, as well as protections available for security researchers acting in good faith.
Rochenergy welcomes reports of potential security vulnerabilities and encourages responsible disclosure via the channels listed on this page.
Rochenergy will not initiate legal action against researchers who conduct good‑faith security research in compliance with this policy. This protection applies only to claims within Rochenergy’s control. It does not authorize any illegal conduct and does not bind third parties.
Rochenergy follows a structured process to ensure proper handling of every vulnerability report:
Acknowledge and log the report for ongoing tracking and follow‑up action.
Reproduce the issue, and evaluate vulnerability severity and potential impact.
Develop appropriate fixes or mitigation measures and complete verification testing.
Share progress updates and communicate final outcomes through official channels.
Rochenergy provides security support in accordance with each product’s lifecycle and applicable security‑support period.
Currently available products receive ongoing security support within their defined support periods.
Discontinued products still within their defined support periods continue to receive security fixes.
Products past their defined support periods no longer receive routine security updates.
* The support period commences on the date a product is placed on the EU market. For further details, please refer to the user manual.
You may report potential security vulnerabilities via email: [email protected]
"*" indicates required fields