Incident Response
Zepp Health takes product security seriously and welcomes security researchers to report potential vulnerabilities, helping us improve the security of our smartwatches and IoT devices (software, hardware, firmware).
Vulnerability Disclosure Policy
We maintain a coordinated vulnerability disclosure strategy intended to reduce the risk of premature disclosure of vulnerability information before appropriate remediation or mitigation measures are available.
The disclosure strategy supports:
- Coordinated vulnerability handling
- Controlled disclosure timing
- Protection of sensitive vulnerability information
- Remediation and deployment coordination
- Communication with reporters and affected stakeholders
Vulnerability Response and Disclosure Process
Our structured approach to handling reported vulnerabilities ensures timely and effective resolution.
Recipient
Monitor and assign received vulnerabilities in a timely manner
Verification
Verify the vulnerability and confirm the exploitability and impact
Solution Development
Provide effective fix solutions or risk remediation measures
Affected Scope Confirmation
Investigate and confirm the complete scope of affected products
Publish Advisory
Review and publish the security advisory for the security vulnerability
Reporting a Vulnerability
Submit your findings
Report discovered security vulnerabilities to our dedicated security team.
sec@zepp.comYour report should contain at least:
- Your organization and contact information
- Products and versions affected
- Description of the potential vulnerability
- Information about known exploits
- Disclosure plans
- Additional information
- Modification or destruction of data
- Service disruption or degradation (e.g. DoS)
- Disclosure of personal, proprietary or financial information
48-hour response
Zepp Health will respond within 48 hours to the vulnerabilities you submit.
PSIRT Roles and Responsibilities
Zepp Health's Product Security Incident Response Team (PSIRT) defines clear roles to ensure vulnerabilities are monitored, tracked, and communicated consistently across all stakeholders throughout the vulnerability lifecycle.
Coordinates vulnerability handling across all stakeholders
The Vulnerability Monitoring / Tracking Coordinator is the central coordination point for vulnerability handling and is responsible for the following throughout the vulnerability lifecycle:
- Coordinating vulnerability handling activities across relevant internal and external stakeholders throughout the vulnerability lifecycle.
- Coordinating communication and information flow between vulnerability reporters, Product Security / PSIRT, Development Teams, Quality Assurance, Release Management, and other relevant stakeholders.
- Continuous monitoring of vulnerability sources, including internal reports, public vulnerability databases, threat intelligence feeds, and third-party component advisories.
- Maintaining the centralized vulnerability tracking system and tracking remediation progress.
- Coordinating the controlled release of security fixes, ensuring that remediation packages, firmware, software updates, and related communications are validated, approved, and distributed according to defined release procedures.
- Monitoring lifecycle status and supportability information associated with third-party software components and upstream dependencies.
Escalation and Decision Making
Escalation criteria are defined based on incident severity and impact, so that critical vulnerabilities, actively exploited vulnerabilities, and significant cybersecurity incidents reach the appropriate management levels without undue delay.
- Confirmed active exploitation
- Significant impact to users or services
- Widespread product exposure
- Regulatory reporting obligations
- Inability to remediate within defined SLA timelines
- Critical decisions — including public communication and regulatory reporting — are made by authorized roles based on predefined thresholds
- Acknowledgement and communication activities are prioritized or accelerated for vulnerabilities assessed as critical, actively exploited, or associated with significant customer or operational impact
Good Faith Security Research
We support good-faith security research and coordinated vulnerability disclosure (CVD) activities that improve the security of our products and services. Our vulnerability disclosure policy provides the following commitments to researchers:
We coordinate responsibly with reporters to investigate and address reported vulnerabilities, and we acknowledge contributions through our Security Bounty program where applicable.
Embargo Management
During coordinated vulnerability handling, we may establish embargo periods to restrict public disclosure of vulnerability information until verified remediation measures are widely available and ready for deployment. Embargo duration and adjustments are managed case by case and may be negotiated with vulnerability reporters, upstream suppliers, and affected stakeholders.
The decision to establish, extend, or terminate an embargo is formally evaluated against the following considerations:
Vulnerability information under embargo is treated as strictly confidential and is restricted to authorized personnel and approved stakeholders under non-disclosure conditions until the formal coordinated disclosure date is reached.
Consistent Handling Across Channels
Every approved reporting channel feeds the same vulnerability management process.
Root Cause Analysis
Root cause analysis is performed for selected vulnerabilities — such as high-severity, high-impact, or recurring issues, or where the PSIRT or Security Team determines it is warranted.
- The underlying cause of the vulnerability
- Affected products, services, or components
- Relevant exploitation conditions or methods
- Dependency relationships and contributing factors associated with the vulnerability
Risk Acceptance and Remediation Deferral
Where a risk is accepted or remediation is deferred, the decision is recorded with a documented justification.
- The assessed risk level and its acceptability
- Existing mitigating controls or compensating measures
- Applicable technical or operational constraints
- Potential impact on affected products, users, customers, or other relevant stakeholders
Ongoing Communication and Status Updates
We maintain ongoing communication with vulnerability reporters and relevant stakeholders throughout the vulnerability handling lifecycle where appropriate.
- Initial triage completion
- Validation or reproduction activities
- Remediation planning
- Remediation availability
- Coordinated disclosure preparation
- Case closure activities
- Additional updates are triggered by significant changes in vulnerability severity, exploitation status, remediation timelines, disclosure coordination, or other material developments
- For critical or actively exploited vulnerabilities, communication is accelerated to support timely coordination and risk reduction
- Communication is maintained throughout the lifecycle, including during escalation situations, personnel transitions, or operational continuity events
Published Compliance Statements
Zepp Health's publicly documented security and vulnerability-handling compliance statements (EU CRA, UK PSTI) are consolidated on a dedicated page.