Security Compliance

Zepp Health publishes the security and vulnerability-handling policies required by applicable regulations, including the EU Cyber Resilience Act (CRA) and the UK Product Security and Telecommunications Infrastructure (PSTI) regime. This page consolidates our publicly documented compliance statements.

Severity Classification

Vulnerabilities are classified by severity to support consistent prioritization and decision-making.

Vulnerabilities are classified based on their severity to support consistent prioritization and decision-making. Our standardized methodology adopts CVSS v4.0, with contextual adjustments, and considers technical impact (confidentiality, integrity, availability), exploitability, attacker capabilities, exposure level, and potential impact on users and systems.

Rating rules: The full severity rating table and scoring details are published on our Security Bounty page, based on the FIRST CVSS v4.0 specification.

Information Confidentiality and Need-to-Know Principle

Vulnerability information handled by Zepp Health's PSIRT is protected according to a strict need-to-know principle to safeguard users, products, and business operations throughout the vulnerability lifecycle.

Information related to vulnerabilities that are under investigation, under remediation, or not yet publicly disclosed is treated as confidential and is shared only with authorized personnel on a need-to-know basis.

Access to such information is restricted to individuals or teams with a legitimate business, security, engineering, operational, legal, or management requirement to support vulnerability handling, remediation, disclosure coordination, or regulatory obligations.

Authorized Access — Legitimate Requirement Basis

Disclosure of confidential vulnerability information is limited to personnel or teams demonstrating a legitimate need across one or more of the following areas:

  • Business — to support vulnerability handling and product decisions
  • Security — Product Security / PSIRT and security operations
  • Engineering — development and remediation of affected components
  • Operational — release management, deployment, and service operations
  • Legal — regulatory reporting and legal obligations
  • Management — oversight, escalation, and decision authority

Confidentiality and Technical Safeguards

Zepp Health applies the following confidentiality and technical safeguards to protect vulnerability-related information.

Information related to identified or suspected vulnerabilities — including unpublished technical details, exploit methods, proof-of-concept (PoC) code, remediation status, and affected customer information — is treated as confidential security information until appropriate remediation or mitigation measures are available.

The following safeguards strictly apply:

Security Channel
Web-based vulnerability reporting forms, vulnerability management portals, APIs, and other web-based communication channels use HTTPS with TLS 1.2 or later. Secure communication services use cryptographic algorithms, certificates, and cipher suites that follow best practices.
Integrity Control
Vulnerability-related communications utilize mechanisms that provide message integrity protection and detection of unauthorized modification during transmission.
Role-Based Access Control (RBAC)
Access to vulnerability records, related tracking systems, and communication channels is restricted to authorized personnel with a legitimate business need, including restricted distribution of technical vulnerability details prior to coordinated disclosure.
Restricted Distribution
Technical details of vulnerabilities are not shared externally or internally beyond the necessary remediation team prior to authorized coordinated disclosure approval.
Approved Channels
All vulnerability-related communications and data exchanges utilize approved, monitored, and secure internal communication channels.
Evidence Protection
All vulnerability reports, validation evidence, and remediation records are securely stored and retained in accordance with internal information protection requirements.

Security Update Policy

The Security Update Policy defines how security updates are developed, validated, and delivered to address identified vulnerabilities — ensuring they are provided in a secure, timely, and reliable manner.

Security-related updates, patches, and remediation releases addressing identified vulnerabilities are made available to users through official update mechanisms without additional charge under normal supported-product usage conditions, unless otherwise agreed for tailor-made products with digital elements. We do not require additional subscription fees, premium service enrollment, or separate licensing payments solely for access to security vulnerability remediation updates applicable to supported products.

Timely delivery: "Timely" is defined by severity-based remediation targets — the customer-facing patch release window from fix readiness through validation, regression testing, staged rollout, and coordinated disclosure preparation. Published targets: Critical within 30 days, High within 60 days, Medium within 90 days, and Low within 180 days. See our Security Bounty page for the full Target Remediation Time table.

Security Update Package Integrity

Security update packages are protected by integrity verification controls to ensure they reach users unaltered.

Integrity Verification Controls
  • Digital signatures
  • Cryptographic hash validation
  • Signed manifests or equivalent integrity verification mechanisms
  • Security channels implemented with integrity (e.g., HTTPS)
Channel-based integrity: Where digital signatures or signed manifests are not applicable to a particular distribution mechanism, integrity is ensured by the secure transport channel (HTTPS) with enforced integrity protection — so updates remain tamper-protected even when package-level signing is not used.