Vulnerability Disclosure Programme

orange line

Path 14

PURPOSE

Micropower Group (hereafter referred to as “Micropower”, “we”, or “our”) develops advanced battery and charging solutions that help industries move towards a more sustainable, electrified future. We enable reliable energy solutions for a wide range of industrial applications and support our partners as they modernise their products towards increased sustainability.

Our core values guide how we design and develop our products, how we collaborate, and how we evolve. We are dedicated to solving real-world challenges with integrity, always striving for solutions our partners can trust. We adapt when industries and technologies evolve, ensuring our solutions remain resilient over time.

Security is part of that commitment. If you believe you have identified a vulnerability in a Micropower product, we encourage you to report it to us. Our Product Cybersecurity and development teams will make best efforts to acknowledge, investigate, and resolve valid reports in a timely manner.

SCOPE

IN SCOPE ASSETS

All Micropower products.

OUT OF SCOPE ASSETS

  • Micropower IT infrastructure, corporate systems, and websites
  • Third party standalone systems or infrastructure that are not developed, operated, or distributed by Micropower

IN SCOPE VULNERABILITY TYPES

  • Remote code execution
  • SQL injection
  • Privilege escalation to admin level
  • XML injection
  • Insecure direct object reference
  • Other software-related vulnerabilities, particularly those related to safety

OUT OF SCOPE VULNERABILITY TYPES

  • Results that primarily arise from social engineering (e.g. phishing, vishing)
  • User interface and user experience errors, spelling and grammar errors
  • Denial of service attacks
  • Findings without a realistic exploitation path or demonstrable security impact

SAFE HARBOUR

Micropower will not pursue legal action against researchers who discover and report vulnerabilities in good faith, provided they comply with the terms of this policy. This includes refraining from accessing data beyond what is necessary to demonstrate the vulnerability, and avoiding actions that could harm Micropower, its customers, or its partners. If in doubt, contact us before proceeding.

HOW TO SUBMIT A REPORT

Send an email to Micropower Product Cybersecurity: product.cybersecurity@micropower.se and include the information below. You may also report vulnerabilities, anonymously where requested, through the CSIRT designated as coordinator for coordinated vulnerability disclosure in your country. In Sweden, this is CERT-SE (www.cert.se).

MANDATORY

  • Contact information: a way to contact you in case we have questions
  • Product identification: the affected Micropower product or solution, including, if possible, product/model number, and hardware or software version
  • Product origin: Where you have encountered or obtained the product
  • Vulnerability description: detailed technical description of the identified vulnerability
  • Reproduction steps: clear steps that allow us to replicate the issue
  • Proof of concept: screenshots, code or other evidence demonstrating the vulnerability
  • Impact assessment: your assessment of the potential security or safety impact

OPTIONAL

  • Additional information: any additional information you wish to share (for example for Hall of Fame)
  • Remediation suggestion: if you have a solution you would like to propose

RESPONSE TIMELINE

Following receipt of your report our Product Cybersecurity representative will make their best effort to follow the timelines below.

Milestone Timeline Details
Initial Response 10 business days Acknowledgement of submission
Triage 60 business days Assessment and severity classification
Resolution Depends on severity and complexity We will keep you updated throughout the process

Response time might be affected during public holiday periods.

Please note: for vulnerabilities assessed as Critical or actively exploited, Micropower's internal teams may need to prioritise containment and regulatory reporting obligations (which carry their own strict, short deadlines) ahead of substantive communication with you. This means that, counterintuitively, the most severe reports may sometimes see slower personal follow-up during the initial period, even though internal work is proceeding urgently. Acknowledgement of receipt will still reach you within the first-response timeline; a detailed response on findings and remediation may take longer in these cases. We appreciate your patience and will keep you updated as soon as we are able.

WHO CAN PARTICIPATE

Participation in this programme is voluntary. By participating you agree to the terms set out in this policy. If you cannot comply with the terms set out in this policy your participation will not be considered.

You must meet the following criteria:

  • You must be of the legal age of majority in your country of residence or submit permission from your legal guardian.
  • You are not a registered resident of any country subject to embargo or sanctions by the European Union, Switzerland or the United Nations.
  • You are not an employee of Micropower or an employee of a third-party organisation acting on behalf of Micropower (e.g. suppliers, consultants).
  • You are not a family member of a Micropower employee, or a family member of an employee of a third-party organisation acting on behalf of Micropower.
  • This is not a paid bug bounty programme. Micropower does not offer monetary rewards or other financial compensation for vulnerability reports. Recognition is limited to the Hall of Fame (see below), where the reporter opts in.

HALL OF FAME

Micropower wishes to acknowledge the security researchers who are the first to responsibly report a specific valid vulnerability. Your support helps us enhance the security of our products and solutions. This acknowledgement is Micropower's sole form of recognition for reports submitted under this programme; no monetary reward is offered.

If you wish to be recognised, you may provide your name and professional link (e.g. LinkedIn) for inclusion. Recognition is published when the vulnerability has been mitigated.

Note that a request for removal of personal data will also lead to removal of your information from the Hall of Fame.

CONFIDENTIALITY

Any information you access, acquire, receive, or collect about Micropower, its affiliates, customers, users or employees (hereafter referred to as “Confidential Information”) must be kept confidential and used only for the purpose of submitting your report. You may not use, disclose, or distribute Confidential Information without our prior consent.

Your submission, including all Mandatory and Optional information under “How to submit a report”, apart from your contact information, must be treated as Confidential Information. You must not publish, discuss, or disclose the submission or the vulnerability to any third party until you have received a notice that the vulnerability has been mitigated, and even then, only with Micropower’s written consent.

The confidentiality obligations set out in this section do not prevent you from reporting the vulnerability, including any related Confidential Information strictly necessary for that purpose, to a CSIRT designated as coordinator for coordinated vulnerability disclosure in accordance with Article 12(1) of Directive (EU) 2022/2555 (NIS2 Directive). Such reporting shall not be considered a breach of the confidentiality obligations under this section.

INTELLECTUAL PROPERTY

For the purpose of this programme, “Intellectual Property Rights” denotes all rights to patents, trademarks, know-how, trade secrets and any other intellectual property rights in any region of the world.

Nothing in this programme grants you any Intellectual Property Rights or other rights or licences to any Micropower products. You acknowledge that Micropower shall own all content or data revealed in this submission.

YOUR PERSONAL DATA

Micropower acts as the data controller for personal data processed in connection with this programme.

WHAT PERSONAL DATA DO WE COLLECT AND WHY

When you report a vulnerability, we will process the following personal data:
  • Contact information that you have submitted to us (see Mandatory and Optional sections of “How to submit a report”). This information will be used to contact you during the investigation.
  • Any information you provide regarding the reported vulnerability such that you can be identified, directly or indirectly. This information will be used for the purpose of the investigation.
  • Any communication between you and Micropower in relation to the vulnerability report. This information will be used to collect information during the investigation and to keep you updated about the progress.

DATA RETENTION OF YOUR PERSONAL DATA

Your personal data is retained for one year after the vulnerability investigation has been completed, to be used to ask additional questions if any arise. The report itself will be saved in anonymised form.

DISCLOSURE OF YOUR PERSONAL DATA

We may disclose your personal data to the following categories of recipients on a strict need-to-know basis:
Service providers supporting Micropower’s activities related to your report (e.g. SOC)
Companies within the Micropower Group that require the information needed for the investigation and mitigation of the reported vulnerability

TRANSFER OF YOUR PERSONAL DATA

We strive to store and process your personal data within EU/EEA. In rare cases, data might be transferred to other regions, for example when sharing the report with the affected customers or partners. When such transfer occurs, we ensure that the equivalent level of protection applies as defined in the General Data Protection Regulation (GDPR).

YOUR RIGHTS

Under the GDPR, you have the right to: withdraw consent or object to the processing of your data, access the personal data we store about you, request rectification or restriction of your data, request portability of your data, request deletion of your data, and file a complaint with a data protection supervisory authority.

To exercise your rights, please contact privacy@micropower.se.

The same contact information applies if you have any questions regarding how we handle your personal data.

CHANGES TO THE HANDLING OF YOUR PERSONAL DATA

This privacy notice is current as of the date shown on the top of this document. We reserve the right to update the notice at any time. Your data will be treated in accordance with the notice at the time your data was collected, unless we have your consent to do otherwise.

Path 14

Kontaktieren Sie uns noch heute

Sind Sie an der Umstellung auf nachhaltige Energielösungen interessiert?
Möchten Sie mehr über Batterien, Lade- oder Spannungswandler erfahren?
Unser engagiertes Expertenteam steht Ihnen gerne zur Verfügung.