Security Compliance
Zepp Health publishes the security and vulnerability-handling policies required by applicable regulations, including the EU Cyber Resilience Act (CRA) and the UK Product Security and Telecommunications Infrastructure (PSTI) regime. This page consolidates our publicly documented compliance statements.
Severity Classification
Vulnerabilities are classified by severity to support consistent prioritization and decision-making.
Vulnerabilities are classified based on their severity to support consistent prioritization and decision-making. Our standardized methodology adopts CVSS v4.0, with contextual adjustments, and considers technical impact (confidentiality, integrity, availability), exploitability, attacker capabilities, exposure level, and potential impact on users and systems.
Information Confidentiality and Need-to-Know Principle
Vulnerability information handled by Zepp Health's PSIRT is protected according to a strict need-to-know principle to safeguard users, products, and business operations throughout the vulnerability lifecycle.
Information related to vulnerabilities that are under investigation, under remediation, or not yet publicly disclosed is treated as confidential and is shared only with authorized personnel on a need-to-know basis.
Access to such information is restricted to individuals or teams with a legitimate business, security, engineering, operational, legal, or management requirement to support vulnerability handling, remediation, disclosure coordination, or regulatory obligations.
Disclosure of confidential vulnerability information is limited to personnel or teams demonstrating a legitimate need across one or more of the following areas:
- Business — to support vulnerability handling and product decisions
- Security — Product Security / PSIRT and security operations
- Engineering — development and remediation of affected components
- Operational — release management, deployment, and service operations
- Legal — regulatory reporting and legal obligations
- Management — oversight, escalation, and decision authority
Confidentiality and Technical Safeguards
Zepp Health applies the following confidentiality and technical safeguards to protect vulnerability-related information.
Information related to identified or suspected vulnerabilities — including unpublished technical details, exploit methods, proof-of-concept (PoC) code, remediation status, and affected customer information — is treated as confidential security information until appropriate remediation or mitigation measures are available.
The following safeguards strictly apply:
Security Update Policy
The Security Update Policy defines how security updates are developed, validated, and delivered to address identified vulnerabilities — ensuring they are provided in a secure, timely, and reliable manner.
Security-related updates, patches, and remediation releases addressing identified vulnerabilities are made available to users through official update mechanisms without additional charge under normal supported-product usage conditions, unless otherwise agreed for tailor-made products with digital elements. We do not require additional subscription fees, premium service enrollment, or separate licensing payments solely for access to security vulnerability remediation updates applicable to supported products.
Security Update Package Integrity
Security update packages are protected by integrity verification controls to ensure they reach users unaltered.
- Digital signatures
- Cryptographic hash validation
- Signed manifests or equivalent integrity verification mechanisms
- Security channels implemented with integrity (e.g., HTTPS)