Vulnerability Disclosure Policy

Introduction

At CenoBots, we are committed to maintaining a high level of cybersecurity for our products and services. We value the contributions of security researchers, customers, partners, and the broader community in helping us identify and address potential security vulnerabilities.

We encourage you to read this policy before submitting a vulnerability report so that reports can be handled safely, efficiently, and responsibly.

Purpose and Scope

This policy sets out the process for reporting potential security vulnerabilities affecting CenoBots products, solutions, and services.

This policy applies to:

  • Commercial cleaning robots marketed or sold by CenoBots.
  • Robot firmware and embedded software.
  • Mobile applications used to configure, operate, or manage CenoBots products.
  • Cloud services, APIs, device management platforms, and customer portals operated by CenoBots.
  • OTA update mechanisms and related update infrastructure.
  • Product documentation or configuration issues that may affect cybersecurity.

Out of Scope

The following are not covered by this policy:

  • Products, services, or systems operated or managed entirely by third parties.
  • Social engineering, phishing, or physical attacks against CenoBots employees, customers, partners, suppliers, or facilities.
  • Denial-of-Service testing or any testing that may disrupt services or product availability.
  • Testing on customer-owned robots, customer sites, or third-party environments without explicit authorization.
  • Actions that may affect the physical safety, navigation, movement, or normal operation of robots in real-world environments.
  • Reports about missing security headers, general best-practice suggestions, or low-impact findings without a demonstrated security impact.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability, please report it to CenoBots at:

it_service@cz-robots.com

CenoBots also publishes a security.txt file to help security researchers identify the official channel for reporting vulnerabilities:

https://www.cenobots.com/.well-known/security.txt

Please include as much of the following information as possible:

  • A detailed description of the vulnerability.
  • Affected product, model, firmware version, app version, cloud service, API, or component.
  • Steps to reproduce the issue.
  • Any proof-of-concept code, logs, screenshots, or network traces, if applicable.
  • Potential impact of the vulnerability.
  • Whether you believe the vulnerability is being actively exploited.
  • Your contact information.
  • Your public key, if you would like us to respond securely.

When submitting a report, please:

  • Use a clear and unobfuscated email subject line.
  • Avoid including sensitive personal data, customer data, or confidential third-party information unless strictly necessary.
  • Attach screenshots or supporting documents as files where possible.

Analysis

Upon receiving a report, CenoBots will begin investigating the potential vulnerability in accordance with our internal procedures. We may contact you for additional information if needed to reproduce or validate the issue.

If the vulnerability is confirmed, CenoBots will assess its severity, affected products and versions, potential customer impact, and required remediation measures.

Handling

If a vulnerability is validated, CenoBots will develop a remediation or mitigation plan. The priority and timeline for remediation will depend on the severity of the vulnerability, the affected products, the potential safety or cybersecurity impact, and the time required for development, testing, and deployment of updates.

Where appropriate, remediation may include software updates, firmware updates, configuration changes, customer advisories, temporary mitigations, or other corrective actions.

For products placed on the European Union market, CenoBots may be required to report actively exploited vulnerabilities or severe cybersecurity incidents to the relevant authorities in accordance with applicable legislation, including the EU Cyber Resilience Act.

Disclosure of a Vulnerability

Once the vulnerability has been analyzed and handled, CenoBots may disclose relevant information to affected customers, partners, regulators, or other relevant parties.

We aim to balance transparency with the need to reduce risk and give affected parties sufficient time to apply necessary fixes or mitigations. Public advisories may therefore be delayed where immediate disclosure could increase cybersecurity or safety risks.

CenoBots may acknowledge individuals, organizations, or companies that voluntarily report valid vulnerabilities and assist us in improving cybersecurity, unless they request anonymity.

Expected Process

  • We will acknowledge receipt of your report within 3-5 business days.
  • We aim to provide an initial assessment within 10 business days.
  • We may provide progress updates where appropriate.
  • Our goal is to resolve critical issues within 90 days of the initial report, depending on severity, complexity, affected products, and validation requirements.
  • CenoBots will inform authorities, customers, partners, or other relevant parties where required by law, regulation, contract, or internal procedures.

Safe Harbor

CenoBots will not take legal action against parties who make a good faith effort to comply with this policy, provided that they:

  • Do not compromise the privacy or safety of our users, customers, employees, or partners.
  • Do not disrupt our services, systems, products, or robot operations.
  • Do not destroy, modify, exfiltrate, or misuse data.
  • Do not access systems, products, or environments without authorization.
  • Do not perform testing that could create physical safety risks or operational disruption.

Public Disclosure

We ask that you do not publicly disclose the vulnerability until CenoBots has had a reasonable opportunity to investigate, remediate, and coordinate disclosure with affected parties.

Please coordinate any public disclosure timeline with us in advance.

Rewards

CenoBots does not currently operate a paid bug bounty program. Submission of a vulnerability report does not create any entitlement to compensation.

Where appropriate, CenoBots may publicly acknowledge valid vulnerability reports unless the reporter requests anonymity.

Throughout the vulnerability disclosure process, you are expected to:

  • Comply with all applicable laws and regulations.
  • Avoid exploiting the vulnerability beyond what is necessary to demonstrate its existence.
  • Avoid disrupting CenoBots services, systems, products, or robot operations.
  • Avoid using high-intensity, automated, or invasive scanning tools.
  • Take all reasonable measures to prevent negative impacts on the safety, privacy, or business operations of individuals or organizations.
  • Avoid accessing, modifying, deleting, or exfiltrating unnecessary, excessive, sensitive, personal, or customer data.
  • Anonymize any sensitive data included in your report.
  • Securely delete any data obtained as part of your vulnerability report once it is no longer required.

This policy does not constitute a waiver of any legal rights or create obligations beyond those explicitly stated. CenoBots reserves the right to take legal action in cases of non-compliance with this policy or applicable law.

Schedule a free demo with us