1. Our Commitment

Cheery Energy takes product security seriously, and is committed to the security of our products and the people who rely on them. We encourage security researchers, users, and other stakeholders to report potential vulnerabilities discovered in our products. We commit to coordinating the handling and disclosure of such vulnerabilities in accordance with this policy.

🛡 Safe Harbour

We will not pursue legal action against individuals who conduct security research in good faith and in compliance with this policy. This commitment is subject to applicable laws and regulations.

This Coordinated Vulnerability Disclosure (CVD) policy explains what is in scope, how to report a vulnerability to us, how we will respond, and how we coordinate public disclosure.

2. Scope

This policy applies to: all products with digital elements that Cheery Energy manufactures.

Eligibility for Remediation

Products and services receive security fixes while they are within their defined support period. A product is not eligible to receive remediation once it is beyond its published end-of-support date.

Out of Scope

Third-party services we do not operate; findings that are already public; reports with no demonstrable security impact; volumetric denial-of-service testing; and social-engineering of our staff or customers.

3. How to Report a Vulnerability

Please report potential vulnerabilities through one of the following channels:

Channel Details
Security Email psirt@cheeryenergy.com — PGP encryption supported. Public key available at cheeryenergy-psirt.com/pgp-key.asc.
security.txt (RFC 9116) cheeryenergy-psirt.com/.well-known/security.txt — Contact, Encryption, Expires fields.

4. Secure & Anonymous Reporting

For submissions involving sensitive details (such as exploit code, customer data, cryptographic keys, or system configurations), please use our encrypted channel. Please encrypt your report using our PGP public key. Initial contact may be made via any channel; upon registration, we will guide you to transition to a secure channel.

You may report anonymously. If you would like a response, please give us a contact address or an alias. We will still accept reports sent through less secure channels — please do not let the lack of encryption stop you from reporting.

Implementation Note

Protect the confidentiality, integrity, authenticity and availability of the contact mechanism using current best-practice cryptography (e.g., HTTPS, signed/encrypted email). Where legacy infrastructure prevents this, keep at least one accessible channel available.

5. What to Include in Your Report

To help us triage and validate efficiently, please include as much of the following as possible:

  1. Product Identification — The affected product or service name, the affected version(s), and the platform or environment (OS, hardware) where applicable.
  2. Vulnerability Description — What the issue is and where it exists, and its type or class (e.g., buffer overflow, SQL injection, improper authentication).
  3. Impact — The potential impact if the issue is exploited (confidentiality, integrity or availability), and a severity assessment or CVSS score if you have one.
  4. Reproduction Steps — Step-by-step instructions to reproduce the issue, and proof-of-concept code or technical evidence if available.
  5. Discovery Information — The date you found the issue and how (testing method, tool, or accidental finding).
  6. Your Contact Information — Your name or alias (you may remain anonymous) and a channel for follow-up.
  7. Disclosure Intent — Whether you intend to publish your findings, and any date you are working toward.

6. What to Expect

After you submit a report, we will:

1

Confirm receipt within 2 working days and assign a tracking ID

2

Aim to triage and validate your report within 7 working days

We will contact you if we need more information.

3

Keep you informed of our progress at reasonable intervals

4

Aim to deliver a resolution within 90 days

Depending on complexity and any third parties involved.

5

Notify you when the vulnerability has been remediated

We may invite you to confirm that the fix resolves the issue.

7. Coordinated Disclosure

We follow a coordinated disclosure approach:

8. Where to Find Our Security Advisories

When a vulnerability has been remediated, we publish a security advisory so that users can assess whether they are affected and how to update. You can find our advisories at:

9. Confidentiality & Recognition

We treat vulnerability reports as confidential. We will not share the personal information you provide with third parties without your explicit consent, except where required by law.

With your permission, we are happy to credit you for your discovery in our advisory or on our acknowledgements page. Let us know if you would prefer to remain anonymous.

10. Safe Harbour & Good-Faith Research

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you.

✅ Good-faith research means, among other things, that you:

  • Only interact with systems or accounts you own or have explicit permission to test.
  • Avoid privacy violations, destruction of data, and any degradation of our services (for example, no denial-of-service testing).
  • Access only the minimum data necessary to demonstrate the issue, and do not store, share or use it.
  • Give us a reasonable time to resolve the issue before any disclosure.