Coordinated Vulnerability Disclosure (CVD) Policy
Copyright © 2026 Mech-Mind Robotics Technologies Co., Ltd. All Rights Reserved
1. Purpose
Mech-Mind Robotics Technologies Co., Ltd. (hereinafter referred to as "the Organization") is committed to ensuring the security of its products with digital elements, and complying with relevant requirements of the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
This Coordinated Vulnerability Disclosure (CVD) policy establishes a process for external security researchers, customers, suppliers, coordinators and the general public to report potential security vulnerabilities in the Organization's products. It also clarifies the Organization's responsibilities and commitments for handling and disclosing such vulnerabilities.
2. Scope
2.1 Products and Services in Scope
The following products, systems and services are covered by this policy:
- Mech-Eye Series 3D Industrial Camera (including firmware and supporting SDK; support period: 5 years from product release)
- Mech-Eye 3D Laser Profiler (including firmware and supporting SDK; support period: 5 years from product release)
- Mech-Vision Machine Vision Software Platform (support period: 5 years from the release date of each major version)
- Mech-Viz Intelligent Robot Programming Environment (support period: 5 years from the release date of each major version)
- Mech-MSR 3D Measurement and Inspection Software (support period: 5 years from the release date of each major version)
- Mech-DLK Deep Learning Software (support period: 5 years from the release date of each major version)
- Mech-Metrics Data Monitoring and Analytics Platform (support period: 5 years from the release date of each major version)
- Mech Mind Official Websites and Online Services - www.mech-mind.com / mech-mind.com.cn
2.2 Out of Scope
The following are not covered by this policy:
- Issues in third-party products, services, or infrastructure that are not owned or operated by the Organization
- Social-engineering, phishing, or physical security attacks
- Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) attacks
- Vulnerabilities in products that have reached end-of-life and are no longer supported with security updates by the Organization
- Vulnerabilities already known to the Organization or actively being remediated
- Functional defects or user-experience issues that pose no security risks
3. Legal Safe Harbor
The Organization commits that it generally will not initiate legal action or report to law enforcement authorities for security research activities conducted in good faith, in strict compliance with the requirements of this policy, in a non-destructive manner, and within the scope authorized by this policy.
Nevertheless, the Organization reserves the right to take necessary measures and make reports as required by law, including but not limited to:
- Reporting or relevant action is mandated by applicable laws and regulations
- Research activities exceed the scope defined in this policy
- Research has caused or is likely to cause harm to users, systems or data
- Activities involve extortion, malicious vulnerability exploitation, unauthorised disclosure of vulnerability information, unauthorised data access or service disruption
This safe harbor protection is subject to the reporter:
- Strictly limiting operations to the minimum necessary to verify the existence of the vulnerability
- Not accessing, modifying, deleting or disclosing the data of other users
- Not exploiting the vulnerability to gain access beyond what is necessary for verification purposes
- Maintaining good-faith, effective communication and cooperation with the Organization
4. How to Report a Vulnerability
The Organization encourages reporters to submit vulnerability reports via its designated security channels. Reports submitted via non-designated channels (e.g. general-purpose email) will also be received and processed by the Organization.
4.1 Submission Channels
Vulnerability reports may be submitted via the following channels:
| Channel | Details |
|---|---|
| Security Email | security@mech-mind.net |
| Security Web Form | https://www.mech-mind.com/security/report |
| Telephone | 400-9696-010 (09:00-18:00 on working days) |
| Customer Service Email | service@mech-mind.net |
security.txt: https://www.mech-mind.com/.well-known/security.txt
PGP key fingerprint: Available at https://www.mech-mind.com/security/pgp-key
4.2 Report Contents
To facilitate efficient triage, reporters are encouraged to provide as much of the following information as practicable:
- Affected Products: Product name, version, platform and/or URL
- Vulnerability Description: Detailed account of the vulnerability and its potential impacts
- Reproduction Steps: Step-by-step instructions, including details of the tools and environment
- Supporting Evidence: Screenshots, network captures, logs or Proof-of-Concept (PoC) code
- Severity Assessment: Optional CVSS v3.1 or v4.0 score
- Contact Information: Email address or other valid means for follow-up communications
4.3 Anonymous Reports
Reporters may submit vulnerabilities anonymously via the secure web form. Anonymity, however, may limit the Organization's ability to provide follow-up communications or public recognition.
5. Vulnerability Handling Workflow
5.1 Receipt
Upon receiving a vulnerability report, the Organization will:
- Acknowledge receipt within 7 working days
- Assign a unique vulnerability-tracking identifier (e.g., MM-VULN-YYYY-NNNN)
- Provide the reporter with initial contact details from its Product Security Incident Response Team (PSIRT)
5.2 Validation
Following acknowledgement of receipt, the PSIRT will complete its initial assessment within 15 working days. During this stage, the Organization will:
- Validate the vulnerability and attempt to reproduce it
- Assess vulnerability severity using CVSS v3.1 or v4.0
- Identify affected products and versions
- Assign an internal processing priority based on risk evaluation
If the information provided in the report proves insufficient for reproduction, the PSIRT will contact the reporter to request supplementary details.
5.3 Vulnerability Risk Assessment
After validation, the Organization will conduct a risk assessment to determine the potential impact, severity and handling priority of the vulnerability.
| Risk Level | Assessment Criteria | Target Response Time |
|---|---|---|
| Critical | CVSS >= 9.0, or confirmed active exploitation | Escalate immediately; temporary fix within 72 hours and issue a full fix within 30 calendar days |
| High | CVSS 7.0 - 8.9 | Fix within 30 calendar days |
| Medium | CVSS 4.0 - 6.9 | Fix within 60 calendar days |
| Low | CVSS < 4.0 | Fix within 90 calendar days |
| Special Circumstances | Circumstances requiring an extension | Notify the reporter in advance and agree upon a revised schedule |
The Organization will inform the reporter of validation results and the assigned vulnerability handling priority.
5.4 Remediation
For validated vulnerabilities, the Organization will formulate, develop, and test appropriate fixes or risk-mitigation measures. Remediation measures may include (but are not limited to):
- Security Patches: Software updates that directly resolve the vulnerability
- Firmware Updates: Security firmware updates for Mech-Eye hardware devices
- Configuration Changes: Product configuration changes that reduce vulnerability risks
- Mitigation Guidance: Temporary risk-reduction guidance for users before a complete remediation is available
- End-of-Life Notification: Notification for relevant users if the affected product is no longer supported for security updates
If the Organization cannot deliver a fix within the target timeframe, it will promptly notify the reporter, provide a revised schedule and temporary mitigation measures.
5.5 Remediation Testing
Before releasing remediation measures, the Organization will conduct necessary testing of all remediation measures, including but not limited to:
- Functional Testing: Verify that the fix has resolved the reported vulnerability
- Regression Testing: Ensure that the remediation does not adversely affect product functionality
- Compatibility Testing: Validate that the fix is applicable to the affected product versions
5.6 Release and Disclosure
After remediation is completed, the Organization will:
- Notify the reporter that the vulnerability has been resolved
- Publish a security advisory or release note, where applicable
- Credit the reporter in public advisories with the reporter's consent
- Update security documentation for affected products
The Organization supports Coordinated Vulnerability Disclosure. Prior to public disclosure, the Organization will negotiate the following items with the reporter:
- The public disclosure date
- The content of the public advisory or statement
- The embargo period required to protect users
Note: The embargo period will be negotiated between the Organization and the reporter on a case-by-case basis.
Organizational security advisories will normally contain:
- Vulnerability Description: Symptom, root-cause analysis, and assigned CVE identifier (if available)
- Severity Assessment: CVSS v3.1/v4.0 score and corresponding risk level
- Affected Products: List of impacted product models and software-firmware version ranges
- Mitigations: Temporary protective measures or workarounds to apply before patch installation
- Remediation: Download locations and installation instructions for patch/firmware-update packages
- Acknowledgements: Credit for the vulnerability discoverer with the reporter's consent
The Organization aims to complete the coordinated disclosure process within 90 calendar days from the date of acknowledgment of the report. If this timeframe cannot be met, the Organization will notify the reporter and agree on a revised disclosure date.
5.7 Post-Release Actions
After a security update is released, the Organization will:
- Monitor all issues related to released remediation measures
- Verify that the vulnerability has been effectively resolved
- Update the final status of the vulnerability record
- Conduct lessons-learned reviews for critical vulnerabilities
6. Ongoing Communications
The Organization commits to maintaining regular communications with reporters and stakeholders throughout the vulnerability handling process:
- Acknowledgement of Receipt: Acknowledge receipt within 7 business days after receiving a vulnerability report
- Progress Updates: Provide the reporter with a progress update at least once every 30 calendar days while the vulnerability is being handled
- Validation Results: Provide the reporter with the assessment results after completion of the initial assessment
- Remediation Timeline: Communicate the expected remediation timeline with the reporter after completion of the risk assessment
- Resolution Notification: Notify the reporter when the security remediation is released
- Public Disclosure: Publish relevant advisories through the Organization's security channels
Security channels include email, web portals and other accessible communication methods as appropriate.
7. Confidentiality
The Organization will keep vulnerability reports confidential. Except as otherwise required by applicable laws or regulations, the Organization will not share personal information provided by the reporter with third parties without the reporter's explicit consent.
8. Data Protection and Privacy
When processing vulnerability reports, the Organization may collect personal information submitted by reporters (such as name and email address). The Organization commits to processing such personal data in accordance with the following principles:
- Legal Basis: The reporter's personal data is processed on the basis of the legitimate interest in maintaining product security
- Data Minimization: Only personal information necessary for processing the vulnerability report will be collected
- Retention Period: The reporter's personal data will be retained for 3 years after the vulnerability is closed and will then be securely deleted
- Data subject rights: Reporters have the right to request access to, correction of, or deletion of their personal data by contacting security@mech-mind.net
- Data Sharing: Unless otherwise required by applicable laws or regulations, the Organization will not transfer personal data to third parties without the reporter's explicit consent. For example, when reporting relevant security incidents to ENISA, only necessary technical information will be provided, without the reporter's identifying information
- International Data Transfers: If data needs to be transferred to a country or region outside the EU, the Organization will ensure that such transfers comply with the requirements of Chapter V of the GDPR
For questions regarding data protection, please contact privacy@mech-mind.net
9. Handling of Non-Vulnerability Reports
If the PSIRT determines after validation that a reported issue does not constitute a security vulnerability, the following actions will be taken:
- Reporter Notification: Inform the reporter of the outcome within 5 working days after completion of the validation
- Rejection Justification: Provide the reporter with specific reasons for non-acceptance (e.g. non-security issues, known defects, out-of-scope under this policy)
- Reassessment: If the reporter disagrees with the PSIRT conclusion, supplementary information may be submitted within 15 working days after receiving the notification and request a reassessment
- Record Closure: Mark the report as closed within the vulnerability management system and record its final status
Common grounds for non-vulnerability classification include:
- The reported behaviour is a functional design product feature, rather than a security defect
- The reported issue is outside the scope of this policy (see Section 2.2)
- The issue could not be reproduced and the reporter has not provided additional information
- The reported vulnerability has already been remediated or is currently being remediated
10. Recognition and Rewards
The Organization currently does not operate a vulnerability bounty program. For reporters who responsibly disclose valid vulnerabilities, the Organization may provide the following forms of recognition or rewards:
- Public acknowledgement on the Organization's security acknowledgments page with the reporter's consent
- Souvenirs or other non-monetary rewards, at the Organization's discretion
All forms of recognition or rewards are determined by the Organization at its sole discretion and are subject to the reporter's compliance with this policy. Reports submitted in violation of this policy are not eligible for recognition or rewards.
Appendix: Document-Revision History
| Version | Date | Author | Change Description |
|---|---|---|---|
| 1.0 | 15 July 2026 | Product Center | Initial release |