Coordinated Vulnerability Disclosure Policy

Release: 2026-09-04 14:38:15

1. Introduction

AgiBot Innovation(Shanghai) Technology Co.,Ltd. is committed to  protecting the security of our products and the safety and privacy of the people who use and rely on them. We welcome reports of potential security vulnerabilities from security researchers, customers and members of the public. This Coordinated Vulnerability Disclosure (CVD) policy explains what is in scope, how to report a vulnerability to us, how we will respond, and how we coordinate public disclosure.


2. Scope 

This policy applies to the following products and services: Robot Products (including full-size humanoid robots, semi-sized humanoid robots, industrial robots, quadruped robots, commercial cleaning robots, dexterous hands, robot main control systems, safety control modules, and local operating systems, robot middleware, control algorithms, and AI models), Terminal Devices, Mobile Applications and APK, Cloud Platforms and Backend Systems, Key Security Scenarios.


Eligibility for remediation: products and services receive security fixes while they are within their defined support period. For example, a product is not eligible to receive remediation once it is beyond its published end-of-support date.


The following are out of scope : third-party services we do not operate; findings that are already public; vulnerabilities already discovered internally;reports with no demonstrable security impact; volumetric denial-of-service testing; and social-engineering of our staff or customers.


3. How to report a vulnerability 

Please report potential vulnerabilities through one of the following channels:


•  Email: psirt@agibot.com.


•  Web form: https://www.butian.net/Company/65395.


•  Telephone: 400 186 0818 , via our customer service, for those who cannot use a written channel.


We provide more than one channel so that reporters can choose a method that suits them, including by telephone where a written channel is not accessible.


4. Secure and anonymous reporting 

To protect sensitive vulnerability information while it is being exchanged:


•  Please submit vulnerability reports through the official reporting channels designated by AgiBot.


•  For reports submitted through a web form or mailbox, AgiBot will apply appropriate transmission-security, access-control, and information-protection measures.


•  For vulnerability reports containing sensitive information, we recommend using the PGP public key provided below to encrypt the report before submission.


•  You may report anonymously. If you would like us to respond or follow up, please provide a valid email address, an alias, or another contact method.


•  We accept reports even when encryption is not available. Please do not delay reporting because you cannot use PGP.


PGP key details PGP 

We encourage finders to use encrypted communication channels to protect the confidentiality of vulnerability reports. Our PGP public key is available at the following link:


<PSIRT PGP Key for Agibot Psirt>


Note: Agibot can exchange encrypted email with you using PGP and GPG


5. What to include in your report 

To help us validate and fix the issue quickly, please include as much of the following as you can:


•  Product identification - the affected product or service name, the affected version(s), and the platform or environment (OS, hardware) where applicable.


•  Vulnerability description - what the issue is and where it exists, and its type or class (e.g., buffer overflow, SQL injection, improper authentication).


•  Impact - the potential impact if the issue is exploited (confidentiality, integrity or availability), and a severity assessment or CVSS score if you have one.


•  Reproduction steps - step-by-step instructions to reproduce the issue, and proof-of-concept code or technical evidence if available.


•  Discovery information - the date you found the issue and how (testing method, tool, or accidental finding).


•  Your contact information - your name or alias (you may remain anonymous) and a channel for follow-up.


•  Disclosure intent - whether you intend to publish your findings, and any date you are working toward.


•  Please do not submit personal information unrelated to vulnerability, production passwords, access tokens, or other sensitive credentials. If such information is necessary, please redact it before submission.


6. What you can expect from us 

After receiving your report, we will:


•  aim to acknowledge receipt within five business days and provide a tracking reference;


•  aim to complete an initial assessment within ten business days and contact you if we need more information;


•  provide progress updates at reasonable intervals;


•  where feasible, aim to provide a remediation or mitigation update within 90 days; the timeline may vary depending on the complexity of the issue and the involvement of third-party suppliers;


•  notify you when the vulnerability has been remediated or mitigated and may invite you to help confirm that the fix resolves the issue.


7. Coordinated disclosure 

We follow a coordinated disclosure approach:


•  We ask that you give us a reasonable opportunity to remediate the issue before disclosing it publicly.


•  We will not publicly disclose details of a reported vulnerability before it has been addressed; any public disclosure will be coordinated and agreed between you and us.


•  Where appropriate we agree an embargo period. Embargo timelines can be adjusted case by case by mutual agreement, including where a coordinator or other vendors are involved.


•  When a fix is released, we publish a security advisory and, where appropriate, request a CVE identifier and submit the information to the EU Vulnerability Database (EUVD).


We follow a coordinated vulnerability disclosure approach:


•  We ask that you give AgiBot a reasonable period to investigate and remediate the issue before public disclosure.


•  Before the issue has been addressed, we generally will not proactively disclose sensitive technical details from the report. Where feasible, we will coordinate the timing and content of public disclosure with you.


•  Where appropriate, we may agree on an embargo period. If a third-party supplier, service provider, or coordinator is involved, the remediation timeline and disclosure arrangements may need to be adjusted.


•  When a fix is released, we publish a security advisory and, where appropriate, request a CVE identifier and submit the information to the EU Vulnerability Database (EUVD).


8. Where to find our security advisories 

When a vulnerability has been remediated, we publish a security advisory so that users can assess whether they are affected and how to update. You can find our advisories at:


• AgiBot official website.


• Product release notes, update notifications, or product update channels.


• CVE records, where a CVE has been assigned, and applicable vulnerability databases.


9. Confidentiality 

We treat vulnerability reports as confidential and uses the information only for vulnerability verification, coordination, remediation, notification, and legally required activities.AgiBot will not share the reporter’s personal information with third parties without the reporter’s explicit consent, except where required by law or necessary for coordinated vulnerability handling.


10. Safe harbour and good-faith research 

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you.


Good-faith research means, among other things, that you:


•  only interact with systems or accounts you own or have explicit permission to test;


•  avoid privacy violations, destruction of data, and any degradation of our services (for example, no denial-of-service testing);


•  access only the minimum data necessary to demonstrate the issue, and do not store, share or use it;


•  give us a reasonable time to resolve the issue before any disclosure.