
VDP
Vulnerability Disclosure Policy (VDP)
Astro-Energy Technology Co., Ltd.
1. Introduction
Protecting our customers from threats to their security is always an important task for Astro-Energy Technology Co., Ltd. As a player in Photovoltaic (PV) inverter, we are committed to providing secure and reliable products and services, and to protecting the privacy and security of user data.
Where appropriate, we may coordinate with component or software suppliers to investigate and resolve reported issues.
We welcome and encourage all reports related to product security or user privacy. We will follow established processes to address them and provide timely feedback.
2. Reporting Security Issues
We strongly encourage organizations and individuals to report any potential security issues to our security team.
�� Email: after_sale@astro-e.com.cn
When submitting a report, please include:
· Product model and software version
· Detailed description of the security issue
· Steps to reproduce (if available)
3. Acknowledgement and Updates
· Acknowledgement of receipt: within 3 business days
· Status updates: provided at least every 7 business days until the issue is resolved
4. Responsible Disclosure Guidelines
1. All parties should comply with applicable laws and regulations.
2. Vulnerability reports should preferably be based on the latest firmware version and written in English.
3. Reports should be submitted via the dedicated communication channel above to ensure timely handling.
4. Reporters must not violate data protection or user privacy when identifying vulnerabilities.
5. Public disclosure should be avoided until a mutually agreed disclosure timeline is reached.
5. Vulnerability Handling Process
Upon receiving a report:
1. The security team will acknowledge the report within the timeframe described above.
2. The report will be assessed to determine validity, severity, and impact.
3. Additional information may be requested from the reporter where necessary.
4. Once confirmed, a remediation plan will be developed and implemented.
We aim to remediate confirmed security issues in a timely manner. Remediation timelines may vary depending on severity, complexity, and deployment constraints.
6. Security Advisory
Security advisories may be issued when:
1. A vulnerability is assessed as critical and remediation is available;
2. A vulnerability is actively exploited or poses significant risk to users.
Security Update Support Period
7. Defined Support Period
This section describes the minimum period for which security updates will be provided.
Long-term Support Time Period: From the initial product release date, each product is guaranteed to receive security update support for at least the following durations. During this period, we will regularly review and address any issues that may affect product security.
· Photovoltaic (PV) inverter : 5 years
For each product listed below, security updates will be provided until the stated end date.
Photovoltaic (PV) inverter
Model | Security Update Support End Date |
TM-L800Mi | 31 January 2031 |
8. Scope of Security Updates
Security updates include software updates that protect or enhance product security, including updates addressing reported or identified vulnerabilities.
Security updates apply to:
· Product hardware capable of receiving updates
· Pre-installed software
· Required software for intended product use
· Manufacturer-provided companion software
9. Support Period Maintenance
The defined support period will not be reduced once published.
If the support period is extended, updated information will be published as soon as practicable.
10. General Notes
This information is provided in English, free of charge, and in a manner that is clear and understandable to users without technical knowledge.
Question? +86-574-8818 8211
-
Financing capacityOur strong core technological strength and research and development capabilities have been the focus of attention and favor of numerous capitals. At present, the angel round has received tens of millions of yuan of investment from wel-known domestic institutional funds, Ningbo Angel Fund, and Asia Green Fund.
-
Technological innovationRelying on the R&D center in Beijing and the independent innovation technology of the Higher Institute of Technology, our company continuously designs and develops photovoltaic application products to meet the needs of the market and users.
-
Quality and cost controlOur products have been tested by our own laboratory and international certification institions to meet the safety and grid-connection standards of different countries.Our company attaches great importance to product quality and production processes, to bring customers the best cost-effective products!
-
Core Technology TeamCore technical team members have 5 doctoral degrees and 7 master's degrees; 1 senior professor,4 research associates, all of whom are professionals in related fields, leading the industry's technological development, and have been recognised and awarded by authoritative institutions for many times.
