Security

Software Security and Mechanism

Security architecture, support period, coordinated vulnerability disclosure (CVD), and security advisories for SOARING SUNSHINE EVSE products, cloud platforms, and related systems.

≥5y
Minimum Security Support Period
72h
Report Acknowledgment Target
2w
Minimum Status Update Cadence
OTA
Signed Security Update Delivery

General Security Architecture

Our security model is applied consistently across deployment types—from single-site installations to large commercial networks—and connection methods including Wi-Fi, Ethernet over PLC, and 4G LTE-M.

🔒

End-to-End Encryption

Data transmissions are encrypted to protect communications between devices, mobile apps, and cloud services.

👥

Role-Based Access Control

Access is restricted by role so operators, administrators, and end users only reach authorized functions.

📄

Digitally Signed Firmware

Firmware packages are encrypted and digitally signed to ensure integrity and authenticity on every device.

🔐

Secure Device Authentication

Built-in mechanisms verify device identity before connection to management platforms or configuration updates.

Support Period & Security Updates

Aligned with our internal vulnerability-handling policy and CRA support-period expectations.

Defined Support Period

  • Minimum duration: At least 5 years from the date the product is placed on the market, or for the product’s expected use time if that period is demonstrably shorter.
  • Publication: The support period is stated in product user information. Once published for a product placed on the market, the declared support period will not be shortened; it may be extended.
  • Security updates: During the support period, security updates are provided to users free of charge (except where otherwise agreed for tailor-made business products).
  • End-of-support notice: Users will be notified at least 6 months before the support period ends, with guidance on residual risk and recommended next steps.
  • Delivery: Security updates are distributed as signed packages, typically via over-the-air (OTA) update, accompanied by advisory information and installation guidance.
Manufacturer Security Update Commitment Vulnerability Reporting Channel
SOARING SUNSHINE PTE. LTD.
  • ≥5 years security support from placing on the market
  • Free-of-charge security updates during the support period
  • Remediation targets by severity (see table below)
  • ≥6 months advance notice before end of support
office@sgsoaring.com
Web report form

Remediation Timeline Targets

Targets follow our internal vulnerability-handling and CVD policies (severity based on CVSS). Initial assessment [VRF] is aligned to ≤24 hours (target) / ≤72 hours (latest)—not business days. Complex supply-chain cases may require coordinated extension for later stages, with written confirmation to the reporter where applicable.

Severity CVSS (ref.) Acknowledgment [RCP] Initial Assessment [VRF] Remediation Decision [RMD] Fix / Advisory Target [RLS]
Critical 9.0–10.0 ≤72 hours ≤24h target / ≤72h latest 10 business days 30 days
High 7.0–8.9 ≤72 hours ≤24h target / ≤72h latest 15 business days 60 days
Medium 4.0–6.9 ≤72 hours ≤24h target / ≤72h latest 20 business days 90 days
Low 0.1–3.9 ≤72 hours ≤24h target / ≤72h latest 30 business days 180 days

Security Advisories

After a security update is available, we publish advisory information including a vulnerability description, affected products/versions, impact and severity, and clear remediation guidance for users. Publication may be delayed in duly justified cases until users have had an opportunity to apply the patch.

ID / CVE Title Severity Affected Products Published Status
No security advisories have been published at this time. Fixed vulnerabilities will be listed here with description, severity, affected versions, and remediation guidance.

Coordinated Vulnerability Disclosure (CVD) Policy

This public CVD summary is aligned with our internal coordinated vulnerability disclosure and vulnerability-handling processes. Do not publicly disclose unfixed issues.

  • Scope: Security issues in SOARING SUNSHINE EVSE products, related official firmware/software, cloud services, and this website. We generally do not accept reports of already-public fixed issues, third-party products not integrated by us, social-engineering-only findings, or customer-modified / EOL software.
  • How to report: Prefer the form below or email office@sgsoaring.com. Encrypted channels (e.g. PGP) may be used for sensitive details when published on this page.
  • Required information: Vulnerability description (EN/ZH), affected product and version, reproduction steps or test method, and impact analysis. PoC, CVSS suggestion, and suggested fix are optional but helpful.
  • Acknowledgment: We aim for an initial channel response promptly (target within 24 hours for the public inbox / web form) and a formal acknowledgment with tracking ID within 72 hours.
  • Initial assessment [VRF]: Complete preliminary validation and impact analysis with a target of ≤24 hours, and no later than ≤72 hours (aligned with awareness / CRA Art.14 timing expectations)—not measured in business days.
  • Status updates: We provide progress updates to the reporter at least every 2 weeks until resolution, notify immediately on material milestones, confirm the remediation plan with the reporter when ready, and notify the reporter before advisory publication.
  • Remediation: Fix/advisory targets follow the severity table above (Critical 30 / High 60 / Medium 90 / Low 180 days).
  • Embargo: Standard coordinated disclosure embargo is 30–90 days after acknowledgment (default 90 days), adjustable by written agreement based on severity, fix complexity, active exploitation, and supply-chain dependencies.
  • Anonymous reports: Anonymous submissions are accepted. We may be unable to follow up or provide public acknowledgment if no contact method is available.
  • Safe harbor: We will not pursue legal action against researchers who act in good faith to improve security, do not access or destroy third-party data, do not cause service disruption, follow this CVD process, and report within 90 days of discovery—excluding malicious exploitation, sale of vulnerability details to third parties, or other unlawful conduct.
  • Acknowledgment / Hall of Fame: With the reporter’s consent, valid contributions may be credited in the related advisory.

Friendly Reminder

  • Install updates promptly and obtain firmware/apps only from official SOARING SUNSHINE channels.
  • Test safely: Do not perform destructive testing on production systems; use isolated or authorized environments only.
  • Official sources: Security policy and advisory updates are published on this page; related announcements may also appear on News.

Report a Vulnerability

If you discover a security issue in SOARING SUNSHINE chargers, cloud services, or this website, submit the form below or email office@sgsoaring.com. For anonymous reports, you may enter “Anonymous” as the name; a contact email is recommended if you want status updates.