Report a Suspected Vulnerability

Linyang Energy has established a well-regulated process for the reception, verification, handling, and disclosure of security vulnerabilities. We welcome and encourage, on an ongoing basis, security researchers, industry security organizations, partners, customers, and suppliers around the world to report to the Linyang Energy PSIRT any security vulnerabilities and potential security risks identified in our energy storage cabinets, DC compartments, and AC compartments and their associated PPC, EMS, and Smart Cloud Platform, as well as smart meters, communication modules, new-energy photovoltaic products, systems, and solutions.

To ensure the efficient and transparent handling of vulnerabilities, we have established a standardized response timeline: under normal circumstances, receipt of a vulnerability report will be acknowledged by email within one (1) business day of submission ("T+1"), and the validity of the vulnerability and preliminary risk assessment will be completed within seven (7) business days ("T+7"), with the findings communicated to the reporter. Throughout the subsequent phases of remediation, version verification, and security advisory publication, the PSIRT will continue to update the reporting party on the latest progress, with priority given to the handling of High and Critical severity vulnerabilities.

Linyang Energy strictly complies with national laws, regulations, and cybersecurity compliance requirements, and adopts reasonable and effective technical and organizational measures to protect all vulnerability data and interaction information received. Except where disclosure is mandated by laws or regulations or explicitly requested by affected customers, no confidential information of the kind described above will be disclosed, shared, or released to any third party without authorization.

With respect to the personal information submitted by vulnerability reporters (including name, contact details, and affiliated organization), such information will be used solely for the purposes of vulnerability handling communication, progress updates, and public acknowledgment (where applicable), and will never be used for commercial promotion, external sharing, or any other unrelated purposes. Without the express written consent of the reporter, Linyang Energy strictly prohibits the disclosure of the reporter's personal identity information to any third party, thereby fully safeguarding the privacy rights of security researchers.