Vulnerability Disclosure Policy of Marstek

Version 1.0

1. Purpose

This Vulnerability Disclosure Policy establishes the principles and procedures by which Marstek receives, evaluates, manages, and remediates security vulnerabilities.

The purpose of this policy is to enhance product security, protect user data, and maintain the integrity and reliability of Marstek products and services.

2. Scope

This policy applies to all:

It is applicable to users, developers, external security researchers, partners, and any individual or entity reporting a potential security vulnerability.

3. Policy Statement

Marstek is committed to safeguarding user privacy and maintaining strong security standards. We encourage good-faith reports of potential security vulnerabilities and pledge to evaluate and remediate valid submissions promptly, transparently, and responsibly.

We do not tolerate malicious activity, exploitation, or unauthorized access attempts. Reports must be submitted through the approved process outlined in this policy.

4. Reporting a Security Vulnerability

Individuals who believe they have identified a security vulnerability must submit their report through the Vulnerability Report Form available on the Marstek Vulnerability Management page.

Reports should include, to the extent possible:

All information submitted will be handled confidentially.

5. Vulnerability Handling Process

Marstek follows an internal vulnerability management process aligned with ISO/IEC 30111 and evaluates all reported issues using CVSS v3.1 scoring standards.

The process includes the following stages:

  1. Information Request: Marstek may request additional confidential and detailed information to support the investigation.
  2. Verification and Validation: Marstek investigates the reported issue and validates whether a genuine vulnerability exists.
  3. Remediation: Once validated, Marstek develops a fix and conducts cross-product verification to ensure there is no unintended impact.
  4. Deployment of Fix: A remediation update, typically delivered via OTA (over-the-air), is released to the affected products.
  5. Post-Deployment Monitoring: Product performance and stability are monitored following the release to confirm successful mitigation.

Marstek prioritizes vulnerability remediation according to severity, environmental constraints, and hardware limitations.

6. Roles and Responsibilities

7. Acknowledgement and Communication

Marstek will acknowledge receipt of all valid reports and may provide follow-up communication where appropriate.

Public disclosure of vulnerabilities may occur only after remediation is completed and must follow coordinated disclosure principles.

8. Legal and Conduct Expectations

Reporters must avoid:

Good-faith research conducted within these boundaries will not be subject to legal action.

9. Appreciation

We thank all individuals and organizations who responsibly report security vulnerabilities. Your efforts directly contribute to improving the safety and reliability of Marstek products and protecting our global user community.