External Coordinated Vulnerability Disclosure (CVD) Policy
Effective date: September 1, 2026;
Last updated: September 1, 2026
1. Introduction and Purpose
Our Product Security Incident Response Team (PSIRT) fully recognizes the importance of product security to our users. We welcome assistance from security researchers, industry experts, and the general public in discovering potential vulnerabilities in our products. We commit to providing "Safe Harbor" protection—promising not to pursue legal action—for reporters who follow the procedures in this policy and do not cause actual harm to users.
2. Scope
This policy applies to all online-connected devices manufactured/operated by our company and their associated Remote Data Processing Solutions (RDPS), including but not limited to:
a. All models of hardware products.
b. All versions of companion mobile applications.
c. Cloud interfaces used to provide backend services.
3. Reporting Channels and Contact Information
Our Product Security Incident Response Team (PSIRT) recognizes the critical importance of product security to our users.
Our Product Security Incident Response Team (PSIRT) maintains multiple channels for vulnerability reports and accepts anonymous submissions.
Security Email: cvd-cra@tes-tec.com (PGP encryption recommended).
4. Recommended Report Content
To help us quickly verify and remediate vulnerabilities, we recommend including the following in your report:
a. Product Identification: Affected product model, firmware version, or URL.
b. Vulnerability Type: Such as Denial of Service (DoS), unauthorized access, sensitive information disclosure, etc.
c. Proof of Concept (PoC): Specific steps, screenshots, or videos to reproduce the vulnerability.
d. Potential Impact: Your assessment of the impact the vulnerability could have on users.
5. Communication Process and Expected Timelines
Receipt Acknowledgement: We will send you an acknowledgement receipt within 3 to 5 business days of receiving the report.
Status Updates: During verification and remediation, we will provide you with a progress update at least every 2 to 3 business days.
6. Coordinated Disclosure Strategy
We adhere to the principle of "Coordinated Disclosure":
a. Reporters must not publicly disclose any vulnerability details before an official patch or mitigation measure is released.
b. We typically release an official security advisory within one week following the release of a fix.
c. TES does not offer a security vulnerability bounty program.
7. Secure Communication
We recommend using encrypted means to transmit sensitive information.
You can download our company's PGP public key here: https://www.tes-tec.com/upload/menu_54/TES-PGP-Public-Key.zip 。
























关闭返回