Incident Response

Zepp Health takes product security seriously and welcomes security researchers to report potential vulnerabilities, helping us improve the security of our smartwatches and IoT devices (software, hardware, firmware).

Vulnerability Disclosure Policy

We maintain a coordinated vulnerability disclosure strategy intended to reduce the risk of premature disclosure of vulnerability information before appropriate remediation or mitigation measures are available.

The disclosure strategy supports:

  • Coordinated vulnerability handling
  • Controlled disclosure timing
  • Protection of sensitive vulnerability information
  • Remediation and deployment coordination
  • Communication with reporters and affected stakeholders

Vulnerability Response and Disclosure Process

Our structured approach to handling reported vulnerabilities ensures timely and effective resolution.

Recipient

Monitor and assign received vulnerabilities in a timely manner

Verification

Verify the vulnerability and confirm the exploitability and impact

Solution Development

Provide effective fix solutions or risk remediation measures

Affected Scope Confirmation

Investigate and confirm the complete scope of affected products

Publish Advisory

Review and publish the security advisory for the security vulnerability

Reporting a Vulnerability

Mailbox

Submit your findings

Report discovered security vulnerabilities to our dedicated security team.

Your report should contain at least:

  • Your organization and contact information
  • Products and versions affected
  • Description of the potential vulnerability
  • Information about known exploits
  • Disclosure plans
  • Additional information
Attention: Zepp Health does not tolerate any activity that may interfere with legitimate users or violate applicable regulations. The following activities are prohibited:
  • Modification or destruction of data
  • Service disruption or degradation (e.g. DoS)
  • Disclosure of personal, proprietary or financial information
Response Time

48-hour response

Zepp Health will respond within 48 hours to the vulnerabilities you submit.

Actual response time may vary depending on the risk level and complexity of the vulnerability.

PSIRT Roles and Responsibilities

Zepp Health's Product Security Incident Response Team (PSIRT) defines clear roles to ensure vulnerabilities are monitored, tracked, and communicated consistently across all stakeholders throughout the vulnerability lifecycle.

Vulnerability Monitoring / Tracking Coordinator

Coordinates vulnerability handling across all stakeholders

The Vulnerability Monitoring / Tracking Coordinator is the central coordination point for vulnerability handling and is responsible for the following throughout the vulnerability lifecycle:

  • Coordinating vulnerability handling activities across relevant internal and external stakeholders throughout the vulnerability lifecycle.
  • Coordinating communication and information flow between vulnerability reporters, Product Security / PSIRT, Development Teams, Quality Assurance, Release Management, and other relevant stakeholders.
  • Continuous monitoring of vulnerability sources, including internal reports, public vulnerability databases, threat intelligence feeds, and third-party component advisories.
  • Maintaining the centralized vulnerability tracking system and tracking remediation progress.
  • Coordinating the controlled release of security fixes, ensuring that remediation packages, firmware, software updates, and related communications are validated, approved, and distributed according to defined release procedures.
  • Monitoring lifecycle status and supportability information associated with third-party software components and upstream dependencies.
Report a vulnerability: Researchers can disclose issues to sec@zepp.com, via our RFC 9116 security.txt, or through the Security Bounty submission flow. The Vulnerability Monitoring / Tracking Coordinator ensures each report is routed and tracked per the process above.

Escalation and Decision Making

Escalation criteria are defined based on incident severity and impact, so that critical vulnerabilities, actively exploited vulnerabilities, and significant cybersecurity incidents reach the appropriate management levels without undue delay.

Escalation Criteria
  • Confirmed active exploitation
  • Significant impact to users or services
  • Widespread product exposure
  • Regulatory reporting obligations
  • Inability to remediate within defined SLA timelines
Decision Authority
  • Critical decisions — including public communication and regulatory reporting — are made by authorized roles based on predefined thresholds
  • Acknowledgement and communication activities are prioritized or accelerated for vulnerabilities assessed as critical, actively exploited, or associated with significant customer or operational impact
Timeliness and triggers: Escalation may be initiated where acknowledgement timelines are exceeded or communication activities are delayed for critical vulnerability reports. Escalation procedures support timely management involvement for vulnerabilities requiring accelerated disclosure coordination, emergency remediation activities, regulatory notification, or significant stakeholder communication.
Documentation: Escalation records, decisions, and approvals are documented within the vulnerability management process. Escalation procedures also support management awareness and corrective actions where communication timelines, acknowledgement expectations, or disclosure coordination activities are delayed or not achieved as expected.

Good Faith Security Research

We support good-faith security research and coordinated vulnerability disclosure (CVD) activities that improve the security of our products and services. Our vulnerability disclosure policy provides the following commitments to researchers:

Good-Faith Reporting
Our CVD policy welcomes and supports good-faith vulnerability reporting. Reports may be submitted to sec@zepp.com, via our RFC 9116 security.txt, or through the Security Bounty submission flow.
Testing Authorization
We authorize security researchers acting in good faith to conduct non-malicious security testing of our products and services, provided they avoid activities that intentionally disrupt services, violate user privacy, or damage systems, and that they follow coordinated disclosure rather than public disclosure.
Reporter Protections
Researchers who comply with this policy are covered by a safe harbor. Within these boundaries we do not pursue legal action against good-faith research, and reports are handled under documented procedural protections so that reporters are not exposed to undue risk for responsible disclosure.

We coordinate responsibly with reporters to investigate and address reported vulnerabilities, and we acknowledge contributions through our Security Bounty program where applicable.

Embargo Management

During coordinated vulnerability handling, we may establish embargo periods to restrict public disclosure of vulnerability information until verified remediation measures are widely available and ready for deployment. Embargo duration and adjustments are managed case by case and may be negotiated with vulnerability reporters, upstream suppliers, and affected stakeholders.

The decision to establish, extend, or terminate an embargo is formally evaluated against the following considerations:

Remediation Readiness
Availability, validation status, and deployment schedule of security updates, patches, or firmware releases.
Threat Urgency
Existence of public exploits, proof-of-concept (PoC) code, or evidence of active exploitation in the wild.
Vulnerability Profile
Technical severity rating (e.g., CVSS score), complexity of exploitation, and potentially affected components.
Stakeholder Impact
Potential risk to user privacy, operational continuity, critical infrastructure, or broader customer ecosystems if disclosure occurs prematurely.
Regulatory Obligations
Applicable statutory reporting timelines and information-sharing requirements under frameworks such as the EU Cyber Resilience Act (CRA).

Vulnerability information under embargo is treated as strictly confidential and is restricted to authorized personnel and approved stakeholders under non-disclosure conditions until the formal coordinated disclosure date is reached.

Consistent Handling Across Channels

Every approved reporting channel feeds the same vulnerability management process.

Unified ProcessAll reports received through any approved channel are handled using the same vulnerability management process — intake, triage, validation, severity assessment, remediation coordination, disclosure coordination, and closure.
Channel-Neutral TreatmentThe reporting channel used does not influence prioritization, assessment criteria, handling workflow, acknowledgement or response timelines, or remediation activities.
Maintained RecordsRecords of vulnerability reports, workflow activities, status updates, and closure decisions are retained to demonstrate consistent and equitable treatment of reports from all channels.

Root Cause Analysis

Root cause analysis is performed for selected vulnerabilities — such as high-severity, high-impact, or recurring issues, or where the PSIRT or Security Team determines it is warranted.

What RCA Identifies and Documents
  • The underlying cause of the vulnerability
  • Affected products, services, or components
  • Relevant exploitation conditions or methods
  • Dependency relationships and contributing factors associated with the vulnerability
Governance and use: Findings are documented within vulnerability tracking records, remediation documentation, or related security assessment records. The outcomes support remediation planning, vulnerability risk assessment, prevention of recurrence through testing and review, identification of related vulnerabilities, expanded impact analysis, and continuous improvement of the secure software development lifecycle.

Risk Acceptance and Remediation Deferral

Where a risk is accepted or remediation is deferred, the decision is recorded with a documented justification.

Documented Justification Considers
  • The assessed risk level and its acceptability
  • Existing mitigating controls or compensating measures
  • Applicable technical or operational constraints
  • Potential impact on affected products, users, customers, or other relevant stakeholders
Governance: The documented justification is retained within the vulnerability management records to support traceability of the decision.

Ongoing Communication and Status Updates

We maintain ongoing communication with vulnerability reporters and relevant stakeholders throughout the vulnerability handling lifecycle where appropriate.

Status Update Milestones
  • Initial triage completion
  • Validation or reproduction activities
  • Remediation planning
  • Remediation availability
  • Coordinated disclosure preparation
  • Case closure activities
Triggers and Continuity
  • Additional updates are triggered by significant changes in vulnerability severity, exploitation status, remediation timelines, disclosure coordination, or other material developments
  • For critical or actively exploited vulnerabilities, communication is accelerated to support timely coordination and risk reduction
  • Communication is maintained throughout the lifecycle, including during escalation situations, personnel transitions, or operational continuity events
For reports received through the coordinated vulnerability disclosure process, the reporter is informed of the verification outcome — confirmation of a valid vulnerability, inability to reproduce the issue, a request for additional information, a duplicate report determination, or an out-of-scope classification. Such communications are recorded within the vulnerability tracking process.

Published Compliance Statements

Zepp Health's publicly documented security and vulnerability-handling compliance statements (EU CRA, UK PSTI) are consolidated on a dedicated page.

View all statements: See our Security Compliance page for our confidentiality principle, technical safeguards, severity classification methodology, and other published security policies.