< Return to Vulnerability Management Process
Vulnerability Disclosure Policy
Our vulnerability disclosure policy for connected products
We are committed to providing the highest quality products and services, and to ensuring the security of
our customers' information when using our products. Cyber threats are increasingly an obstacle to achieving
these goals; we have a professional security incident response team that coordinates and addresses security
vulnerabilities. If you believe you have found a security vulnerability in one of our products, please
follow our disclosure process to contact iotsecurity@cn.gree.com
We will work with all relevant parties (such as R & D team, legal department, etc.) to deal with the
loopholes in the missed report in a timely manner. It is recommended that you contact us through the
prescribed channels and provide the required relevant information; we will reply within 30 working days
after receiving the vulnerability report. We may regularly update the progress of the problem, and your
contribution will be reflected on our thank you page. We will not bring any action against a person who
reports a vulnerability to us, provided that the person does not publicly disclose the details of the
vulnerability until we have confirmed that the vulnerability has been completely fixed.