Vulnerability Disclosure Policy
Safeguarding against security issues is a top priority for us and we welcome anyone with a security background to report potential security vulnerabilities to us to improve the security of our products and services.
Please report any security vulnerabilities via Contact Support
The Issue description should include at least the following information, ideally as an attachment in this format:
-
Your organization and contact information (non-mandatory)
-
Products and versions affected
-
Description of potential vulnerability
-
Information about known exploits
-
Disclosure plans
Response Time
Upon receipt of the vulnerability you have submitted, we will send you a notification via email within 48 hours to commence the vulnerability response, along with confirmation and feedback on the nature of the vulnerability. The subsequent progress of vulnerability will also be continuously updated .
* Note: Actual vulnerability response time may vary depending on the risk level and complexity of the vulnerability.
Emphasize that, prior to the vulnerability being remediated, both parties shall keep the information confidential until [ELEGOO] publishes a formal security advisory.
Security Update Support Period
We will generally maintain security updates for at least two years from the launch date of a product. However, the security update situation may vary by product, so please pay attention to our announcements.
