The Linyang Energy Product Security Incident Response Team ("PSIRT") is a dedicated unit established by Linyang Energy to address product security vulnerabilities across all business segments of the Group. With the energy storage business at its core, the PSIRT holds overall responsibility for security vulnerability management across the complete product portfolios of Jiangsu Linyang Energy Storage Technology Co., Ltd., Jiangsu Linyang Zhiwei Technology Co., Ltd., and Jiangsu Linyang New Energy Technology Co., Ltd. Specifically, the PSIRT is responsible for the centralized intake, verification, closed-loop remediation, and compliant disclosure of security vulnerabilities affecting the Company's energy storage cabinets, DC compartments, and AC compartments, together with their associated PPC, EMS, and Smart Cloud Platform, as well as smart meters, communication modules, and new-energy photovoltaic products and systems. Through these efforts, the PSIRT ensures the secure and compliant operation of all equipment, control systems, and platforms.
A security vulnerability refers to any security defect or weakness existing in the hardware, software, or system configuration of Linyang Energy's energy storage, smart-metering, and new-energy products. Such vulnerabilities may be exploited by malicious actors to bypass legitimate access controls and thereby obtain unauthorized access to, tamper with, steal, or damage equipment and system resources. This poses a direct threat to the confidentiality, integrity, and availability of data at energy storage sites, smart grids, and new-energy power stations, and exposes users to potential risks with respect to equipment operation, data security, and business continuity.
Linyang Energy has consistently adhered to an open, compliant, and well-governed approach to security. We sincerely welcome security researchers, industry organizations, partner suppliers, and end users to proactively report suspected security vulnerabilities in our products. The PSIRT strictly follows internationally recognized vulnerability management standards, including ISO/IEC 30111 and ISO/IEC 29147, and carries out the entire vulnerability handling lifecycle — intake, verification, assessment and resolution, patch development, and compliant disclosure — in a standardized and disciplined manner.
I. Service Commitments of the Linyang Energy PSIRT
In order to safeguard product security and protect user interests on an ongoing basis, and to standardize the management of vulnerabilities throughout their entire lifecycle, the Linyang Energy PSIRT hereby makes the following commitments:
1. Full-lifecycle security management
In accordance with the IEC 62443-4-1 industrial cybersecurity standard, we have established a security management framework that covers the entire lifecycle of our energy storage, smart-metering, and new-energy product lines, spanning research and development, testing, launch, operations and maintenance, iterative upgrades, and end-of-life retirement. This framework enables us to exercise rigorous control over product security quality from the outset and to strengthen product-level security governance.
2. Routine security testing and proactive remediation
On a regular basis, we conduct security assessments and risk screening of our energy storage cabinets, DC compartments, and AC compartments and their associated controllers, EMS, and cloud platforms, as well as smart meters, communication modules, and new-energy photovoltaic systems. We proactively remediate security vulnerabilities identified in our products and services, eliminating security risks to the greatest possible extent and establishing a stable and reliable security barrier for our users' energy storage sites, smart grids, and new-energy power stations, thereby effectively reducing security risks and mitigating potential losses.
3. Priority handling of high-severity vulnerabilities
With respect to verified product security vulnerabilities, we give priority to the remediation of High and Critical severity issues. Upon confirmation, we immediately assess the scope of impact, and subsequently develop, publish, and disseminate tailored risk mitigation plans and emergency response measures without delay, ensuring that users can implement security protection on their equipment and systems in a timely manner.
4. Compliance-oriented governance
We comprehensively review industry regulatory requirements, applicable laws and regulations, cooperation agreements, and published security standards, and clearly define role-specific responsibilities and compliance obligations in vulnerability management. We maintain a normalized and proactive vulnerability risk management mechanism adapted to the diverse operational scenarios of the energy storage, smart-metering, and new-energy businesses.
5. Continuous improvement
We continuously benchmark against industry-leading practices and iteratively optimize our vulnerability handling processes, management policies, and technical standards. In doing so, we continuously enhance the PSIRT's professional capabilities and management maturity in vulnerability assessment, emergency response, and risk prevention, and strengthen our security response capabilities across the energy storage, smart-metering, and new-energy businesses.
II. How to Submit a Vulnerability
Linyang Energy has established a standardized, closed-loop process for vulnerability intake and handling. Our vulnerability reporting channel is open to the public, and we sincerely invite security practitioners, industry organizations, partners, and users to report suspected security vulnerabilities in our products.
If you identify a security vulnerability in the energy storage, smart-metering, or new-energy products of Jiangsu Linyang Energy Storage Technology Co., Ltd., Jiangsu Linyang Zhiwei Technology Co., Ltd., or Jiangsu Linyang New Energy Technology Co., Ltd., you may submit the relevant information through our official dedicated mailbox at psirt@linyang.com.cn. Submissions are recommended to include: the product category involved, a detailed deion of the vulnerability, the conditions required to trigger it, the specific product model and hardware/software versions affected, a deion of the security impact, network traffic captures, reproduction steps, and your contact information, so that the team can reach out to coordinate and keep you informed of progress.
To ensure the efficient handling of vulnerabilities, the PSIRT has established a standardized response timeline: upon receipt of a vulnerability submission, we will confirm receipt and respond to the submitter by email within one (1) business day ("T+1"); within seven (7) business days ("T+7"), we will complete the verification of the vulnerability's authenticity and the assessment of its risk severity, and share the preliminary findings with the submitter. Throughout the subsequent phases of remediation, testing, and deployment, the PSIRT will continue to proactively track progress and issue corresponding vulnerability disclosures on our official website.
During the entire vulnerability handling cycle, Linyang Energy exercises strict control over access to vulnerability information. All vulnerability data and related details are accessible only to core handling personnel and the relevant business owners, and the scope of information dissemination is strictly limited. In parallel, we request that submitters maintain strict confidentiality regarding all undisclosed vulnerability information until the Company has completed remediation across all affected product lines and released an official solution, thereby ensuring the safe and stable operation of all users' equipment.
Linyang Energy strictly complies with national laws, regulations, and regulatory compliance requirements, and employs reasonable measures including encryption, access isolation, and audit logging to protect the security of submitted vulnerability data and related user data. Except where disclosure is mandated by laws and regulations, required by judicial authorities, or specifically authorized by affected users, Linyang Energy will not disclose, disseminate, or transfer any related vulnerability data to any third party.
III. Vulnerability Response and Handling Process
Upon receiving a vulnerability submission, the Linyang Energy PSIRT will immediately coordinate with the product R&D, testing, operations and maintenance, and supply chain teams to conduct in-depth analysis, authenticity verification, and comprehensive risk assessment of vulnerabilities affecting energy storage, smart-metering, and new-energy products, with priority given to High and Critical severity vulnerabilities. Taking into account the application scenarios of each product, the scale of equipment coverage, and the severity of impact, the team will precisely determine the risk level and define clear remediation priorities.
For vulnerabilities of different risk levels, the team will develop tailored closed-loop remediation solutions, including temporary device-level risk mitigation strategies, firmware and software patch upgrades, system version iterations and optimizations, and guidance on site-level and grid configuration optimization, thereby providing users with practical and executable security protection and remediation solutions.
In addition, across the entire value chain — including in-house product development, outsourced procurement, project delivery, on-site deployment, and day-to-day operations and maintenance — should security vulnerabilities be identified in supplier-provided supporting products or third-party services, Linyang Energy will immediately engage with the relevant partner suppliers to communicate the vulnerability details, urge remediation, and track the progress of resolution through to closure, thereby ensuring the overall security of the system.
IV. Vulnerability Disclosure Policy
In order to protect users' right to be informed and ensure the operational security of their equipment, Linyang Energy has established a standardized mechanism for the public disclosure of vulnerability information, primarily through the publication of official security advisories on its website.
Official security advisories will set out, in full, the risk level of the vulnerability, the affected energy storage, smart-metering, and new-energy product models and version ranges, the core impact of the vulnerability, a deion of the associated risks, temporary mitigation measures, and the official remediation plan, enabling users to promptly identify device risks and complete security remediation and protection in a timely manner. Linyang Energy reserves the right to publish, update, supplement, and revise security advisories.
V. Supplementary Notes
1. The Linyang Energy PSIRT enforces strict confidentiality and access control over all vulnerability-related information, maintains complete audit logs of information flow throughout the process, and prevents any leakage or misuse of vulnerability information, thereby ensuring a fully closed-loop security response.
2. The Linyang Energy PSIRT reserves the right of final interpretation of these security incident response and vulnerability management guidelines.