Vulnerability Disclosure Policy of Marstek
Version 1.0
1. Purpose
This Vulnerability Disclosure Policy establishes the principles and procedures by which Marstek receives, evaluates, manages, and remediates security vulnerabilities.
The purpose of this policy is to enhance product security, protect user data, and maintain the integrity and reliability of Marstek products and services.
2. Scope
This policy applies to all:
- Marstek hardware products
- Marstek mobile and Web software
- Cloud services, APIs, and firmware associated with Marstek
- Any third-party components integrated into the above systems
It is applicable to users, developers, external security researchers, partners, and any individual or entity reporting a potential security vulnerability.
3. Policy Statement
Marstek is committed to safeguarding user privacy and maintaining strong security standards. We encourage good-faith reports of potential security vulnerabilities and pledge to evaluate and remediate valid submissions promptly, transparently, and responsibly.
We do not tolerate malicious activity, exploitation, or unauthorized access attempts. Reports must be submitted through the approved process outlined in this policy.
4. Reporting a Security Vulnerability
Individuals who believe they have identified a security vulnerability must submit their report through the Vulnerability Report Form available on the Marstek Vulnerability Management page.
Reports should include, to the extent possible:
- A clear description of the vulnerability
- Steps to reproduce
- Affected product models, versions, or firmware
- Any supporting technical details, logs, or evidence
All information submitted will be handled confidentially.
5. Vulnerability Handling Process
Marstek follows an internal vulnerability management process aligned with ISO/IEC 30111 and evaluates all reported issues using CVSS v3.1 scoring standards.
The process includes the following stages:
- Information Request: Marstek may request additional confidential and detailed information to support the investigation.
- Verification and Validation: Marstek investigates the reported issue and validates whether a genuine vulnerability exists.
- Remediation: Once validated, Marstek develops a fix and conducts cross-product verification to ensure there is no unintended impact.
- Deployment of Fix: A remediation update, typically delivered via OTA (over-the-air), is released to the affected products.
- Post-Deployment Monitoring: Product performance and stability are monitored following the release to confirm successful mitigation.
Marstek prioritizes vulnerability remediation according to severity, environmental constraints, and hardware limitations.
6. Roles and Responsibilities
- Reporter: Provides accurate, confidential, and good-faith submissions.
- Security Response Team: Investigates, validates, scores, and tracks vulnerability remediation.
- Engineering Teams: Develop and verify fixes across applicable product lines.
- Quality Assurance: Validates stability post-remediation.
7. Acknowledgement and Communication
Marstek will acknowledge receipt of all valid reports and may provide follow-up communication where appropriate.
Public disclosure of vulnerabilities may occur only after remediation is completed and must follow coordinated disclosure principles.
8. Legal and Conduct Expectations
Reporters must avoid:
- Exploiting or abusing the vulnerability
- Accessing user data or systems beyond what is necessary for proof-of-concept
- Publicly disclosing information before remediation is complete
- Performing actions that degrade service availability or product performance
Good-faith research conducted within these boundaries will not be subject to legal action.
9. Appreciation
We thank all individuals and organizations who responsibly report security vulnerabilities. Your efforts directly contribute to improving the safety and reliability of Marstek products and protecting our global user community.