1. Introduction and Purpose
The Company recognizes the importance of product security to its users. We welcome security researchers, industry experts, and users to assist us in identifying potential vulnerabilities in our products. We are committed to providing “safe harbor” protection to reporters who submit vulnerabilities in accordance with this policy and do not cause actual harm to users. In such circumstances, the Company will not initiate legal action against the reporter.
2. Scope
This policy applies to all connected devices manufactured or operated by the Company and their associated remote data processing solutions (RDPS), including but not limited to:
- All hardware products under the [reComputer Series] model range.
- Associated mobile applications with version [V1.0] or later.
- Cloud interfaces used to provide back-end services.
3. Reporting Channels and Contact Information
We provide multiple channels for receiving vulnerability reports and support anonymous submissions:
- Security email: [email protected] (PGP encryption is recommended).
- Online submission form: https://www.seeedstudio.com/security/report (HTTPS supported).
- Anonymous reporting: We respect your privacy. If you prefer to submit a vulnerability report anonymously, you may do so without providing any personally identifiable information.
4. Recommended Report Content
To help us verify and remediate vulnerabilities efficiently, we recommend that each report include the following information:
- Product identification: affected product model, firmware version, or URL.
- Vulnerability type: for example, denial of service (DoS), unauthorized access, or sensitive information disclosure.
- Verification evidence (PoC): specific steps to reproduce the vulnerability, screenshots, or video evidence.
- Potential impact: your assessment of the possible impact of the vulnerability on users.
- Recommended mitigation measures (if available).
- Contact information for follow-up communication.
5. Communication Process and Expected Timeline
- Acknowledgement of receipt: We will send you an acknowledgement within [24H] business days after receiving your report. The acknowledgement will include a unique tracking number.
- Status updates: During verification and remediation, we will provide progress updates at least once every [72H] calendar days.
6. Coordinated Disclosure Strategy
We follow the principle of coordinated disclosure:
- Before an official patch or mitigation measure is released, the reporter should not publicly disclose any vulnerability details.
- In general, we will publish an official security advisory within [time] days after the remediation is released.
7. Secure Communication (Recommended for Higher-Assurance Submissions)
We recommend using encrypted communication methods when transmitting sensitive information. You may obtain the Company’s PGP public key as follows:
PGP Key ID: 0x58D0BECF55BA8A0F
PGP Fingerprint: 823A FC37 B520 F98C 263A 7F46 58D0 BECF 55BA 8A0F
Available for download here: seeed-cvd-pgp-public.asc

