Our commitment to product security — how to report, what to expect, and how we protect those who help us.
Cheery Energy takes product security seriously, and is committed to the security of our products and the people who rely on them. We encourage security researchers, users, and other stakeholders to report potential vulnerabilities discovered in our products. We commit to coordinating the handling and disclosure of such vulnerabilities in accordance with this policy.
We will not pursue legal action against individuals who conduct security research in good faith and in compliance with this policy. This commitment is subject to applicable laws and regulations.
This Coordinated Vulnerability Disclosure (CVD) policy explains what is in scope, how to report a vulnerability to us, how we will respond, and how we coordinate public disclosure.
This policy applies to: all products with digital elements that Cheery Energy manufactures.
Products and services receive security fixes while they are within their defined support period. A product is not eligible to receive remediation once it is beyond its published end-of-support date.
Third-party services we do not operate; findings that are already public; reports with no demonstrable security impact; volumetric denial-of-service testing; and social-engineering of our staff or customers.
Please report potential vulnerabilities through one of the following channels:
| Channel | Details |
|---|---|
| Security Email | psirt@cheeryenergy.com — PGP encryption supported. Public key available at cheeryenergy-psirt.com/pgp-key.asc. |
| security.txt (RFC 9116) | cheeryenergy-psirt.com/.well-known/security.txt — Contact, Encryption, Expires fields. |
For submissions involving sensitive details (such as exploit code, customer data, cryptographic keys, or system configurations), please use our encrypted channel. Please encrypt your report using our PGP public key. Initial contact may be made via any channel; upon registration, we will guide you to transition to a secure channel.
You may report anonymously. If you would like a response, please give us a contact address or an alias. We will still accept reports sent through less secure channels — please do not let the lack of encryption stop you from reporting.
Protect the confidentiality, integrity, authenticity and availability of the contact mechanism using current best-practice cryptography (e.g., HTTPS, signed/encrypted email). Where legacy infrastructure prevents this, keep at least one accessible channel available.
To help us triage and validate efficiently, please include as much of the following as possible:
After you submit a report, we will:
We will contact you if we need more information.
Depending on complexity and any third parties involved.
We may invite you to confirm that the fix resolves the issue.
We follow a coordinated disclosure approach:
When a vulnerability has been remediated, we publish a security advisory so that users can assess whether they are affected and how to update. You can find our advisories at:
We treat vulnerability reports as confidential. We will not share the personal information you provide with third parties without your explicit consent, except where required by law.
With your permission, we are happy to credit you for your discovery in our advisory or on our acknowledgements page. Let us know if you would prefer to remain anonymous.
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you.