Product Security
Coordinated Vulnerability Disclosure Policy
Scope. All Segway-Ninebot products with digital elements placed on the market, including embedded software, mobile applications and remote data processing solutions related to these products. Segway-Ninebot products with digital elements include: electric kickscooters, self-balancing vehicles, eBikes, Navimow robotic mowers, and their software and mobile applications.
Report a Vulnerability
Please use the following channels to report suspected security vulnerabilities in our products, applications, or related services.
- Security Email: product-security@ninebot.com
- Anonymous Reports: Anonymous reports are accepted. However, providing contact information helps us validate the issue and coordinate remediation.
- PGP Public Key: Download
Please report security vulnerabilities primarily via the email address, if email is not convenient, you may also report through the customer service channels in your country or region; your report will be forwarded to our Product Security incident Response Team (PSIRT)
How We Handle Reports
Upon receipt of a report, we review the information provided to determine whether it contains sufficient detail for assessment, verify whether the report identifies a valid security vulnerability, assess its severity and potential impact, identify affected products or versions, and determine appropriate remediation measures.
How to report. Email product-security@ninebot.com with the product name and software version, a description of the vulnerability and steps to reproduce it, and — if known — whether it is public or actively exploited. Anonymous reports are accepted. Where sensitive details are involved (exploit code, customer data, keys, configuration data), we recommend encrypting them with our PGP public key; where convenient, please include your own PGP key so that we can share sensitive information with you securely.
What to Include in Your Report
To help us assess and reproduce the issue, please include as much of the following information as possible:
- Product name and model
- Affected software, firmware, or app version
- Detailed description of the vulnerability
- Step-by-step reproduction instructions
- Expected and actual behavior
- Potential impact
- Proof-of-concept code, screenshots, logs, or network traces, if available
- Your name and contact information (optional for anonymous reports)
- if known-whether it is public or actively exploited
What to expect. We will stay in contact with you throughout the process: we acknowledge your report within 3 business days, provide an initial assessment within 10 business days, and notify you once the vulnerability has been remediated, mitigated, or otherwise closed. We may also share further updates where appropriate, including if there are adjustments to the remediation plan, changes to the disclosure timeline, or delays resulting from coordination with relevant third parties. Vulnerabilities are remediated without undue delay; security updates are provided free of charge.
Coordinated Disclosure and Embargo Period
Confirmed vulnerabilities may be handled under a coordinated disclosure process, especially where a fix is not yet available, where remediation requires coordination across multiple affected products or parties, or where third-party, open-source, or supplier-provided components are involved.Unless otherwise agreed, the default embargo period is 90 business days from confirmation of the vulnerability. This period may be adjusted case by case depending on remediation complexity, supply chain coordination, and the security risk involved. During the embargo period, vulnerability details should not be publicly disclosed before remediation or an advisory is available. After remediation, we may publish relevant information through our Security Advisories and, where appropriate, also share vulnerability information with the EU Vulnerability
Database (EUVD).
Good-faith research. Research conducted in good faith under this policy is authorized: do not access others' data, do not degrade the availability or safety of products in use, comply with applicable law. Segway-Ninebot will not initiate legal action for research conducted in accordance with this policy.
Acknowledgement and recognition.
With your consent, we will acknowledge your contribution in our security advisory or on our acknowledgments page.
Security Advisories
Support Period
- {{filter.filterName}}
- {{option}}
| {{column.headerLabel}} |
|---|
| {{cellValue(row, column)}} |
- {{tableObj.filterList[openFilterIndex].filterName}}
- {{option}}