Vulnerability Reporting
and Security Response

Rochenergy is committed to delivering safe, reliable and intelligent energy‑storage products and solutions for the global energy transition. We regard the cybersecurity of our products and services as a key responsibility. We welcome potential security‑vulnerability reports from users, security researchers and industry partners. Working together, we continuously improve product security and build a trustworthy energy future.

Report Security Vulnerabilities

Our Security Commitments

Security is embedded into our product‑development workflows to protect customers and their connected environments.

Diligent Handling

We carefully review, assess and follow up on every vulnerability report.

Timely Response

We strive to acknowledge receipt of each vulnerability report within two working days.

Clear Communication

We provide timely updates on processing progress and request supplementary information when necessary.

Ongoing Support

We address reported vulnerabilities for the duration of a product’s defined security‑support period.

Coordinated Vulnerability Disclosure Policy

Rochenergy values good‑faith security research. This policy describes how to report potential vulnerabilities, as well as protections available for security researchers acting in good faith.

Responsible Disclosure

Rochenergy welcomes reports of potential security vulnerabilities and encourages responsible disclosure via the channels listed on this page.


Safe‑Harbor Statement

Rochenergy will not initiate legal action against researchers who conduct good‑faith security research in compliance with this policy. This protection applies only to claims within Rochenergy’s control. It does not authorize any illegal conduct and does not bind third parties.


Research Code of Conduct

  • Only test systems, devices and accounts that you own or have been authorized to test, and limit testing to what is necessary.
  • Do not access, modify, retain or disclose other people’s data. Immediately cease testing should you encounter such data.
  • Do not disrupt services, conduct social‑engineering attacks, or exploit vulnerabilities for personal gain or to cause harm.
  • Report vulnerabilities promptly, and allow reasonable time for investigation and remediation prior to any public disclosure.

Vulnerability Handling Process

Rochenergy follows a structured process to ensure proper handling of every vulnerability report:

01

Report Receipt

Acknowledge and log the report for ongoing tracking and follow‑up action.

02

Validation and Assessment

Reproduce the issue, and evaluate vulnerability severity and potential impact.

03

Remediation and Testing

Develop appropriate fixes or mitigation measures and complete verification testing.

04

Communication and Closure

Share progress updates and communicate final outcomes through official channels.

Product Lifecycle and End‑of‑Life Policy

Rochenergy provides security support in accordance with each product’s lifecycle and applicable security‑support period.

Active Products

Currently available products receive ongoing security support within their defined support periods.

Maintained Products

Discontinued products still within their defined support periods continue to receive security fixes.

End‑of‑Support

Products past their defined support periods no longer receive routine security updates.

* The support period commences on the date a product is placed on the EU market. For further details, please refer to the user manual.

Report a Security Vulnerability

You may report potential security vulnerabilities via email: [email protected]

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Drop files here or
Max. file size: 15 MB, Max. files: 3.
    Please remove personal or confidential information unrelated to the vulnerability from submitted materials. Do not send passwords, private keys or personal data not required for investigating the issue.