Marstek Security

At Marstek, we take the security of our products and services seriously. We appreciate the efforts of security researchers and the broader community in helping us identify and address potential vulnerabilities.

We follow the principles of Coordinated Vulnerability Disclosure (CVD) to ensure that reported issues are handled responsibly and that our users remain protected.

Report a Vulnerability

Our Commitments

Accessible Reporting Channels

We provide multiple ways to report security issues, including email, web form, and security.txt, so researchers can choose the method that works best for them.

Professional Triage

Every report is reviewed by our security team. We assess severity, reproduce findings, and work toward a timely resolution.

Ongoing Communication

We keep reporters informed throughout the process—from acknowledgment to remediation and, where appropriate, public disclosure.

If we identify a potentially exploitable vulnerability affecting related products, we will notify users according to the following timelines:
  1. An initial notification will be issued within 24 hours of identification.
  2. General vulnerability information will be provided within 72 hours.
  3. A final vulnerability report will be provided within a maximum of 14 days.

Official Reporting Channels

Through a Web Form

Report Through Web Form

security.txt

security.txt

For sensitive reports, you may use encrypted communication. Our PGP Public Key is available for secure submissions. Please review our Safe Harbor policy before testing.