DATE: 2026/09/11

SEER Robotics Advances EU CRA Compliance with Launch of Coordinated Vulnerability Disclosure Policy

As of September 11, 2026, the vulnerability and serious security incident reporting obligations under the EU Cyber Resilience Act (CRA) officially take effect, requiring manufacturers to establish mechanisms for vulnerability receipt, analysis, and reporting. The main CRA requirements will be fully applicable from December 2027.
In alignment with this regulatory milestone, SEER Robotics has published its Coordinated Vulnerability Disclosure (CVD) Policy, opening vulnerability reporting channels to security researchers, customers, and the public. The policy defines clear timelines and responsibilities across the full vulnerability lifecycle — receipt, validation and triage, remediation delivery, and coordinated disclosure.
This publication marks a key milestone in SEER Robotics' EU CRA compliance journey and establishes a transparent, traceable security collaboration framework for customers and partners worldwide.



Coordinated Vulnerability Disclosure Policy
Document control
Document owner: Overseas Products Department
Version: 1.0
Published date: 2026-09-11
Public location: Coming soon
Classification: Public

Introduction
Shanghai Seer Intelligent Technology Co., Ltd. ("we", "us") is committed to the security of our products and the people who rely on them. We welcome reports of potential security vulnerabilities from security researchers, customers and members of the public. This Coordinated Vulnerability Disclosure (CVD) policy explains what is in scope, how to report a vulnerability to us, how we will respond, and how we coordinate public disclosure.

Scope
This policy applies to all products and services of Shanghai Seer Intelligent Technology Co., Ltd., including but not limited to SRC series robot controllers, self-developed AMRs and mobile robots, charging stations, scheduling systems and other products with network communication capabilities.
Eligibility for remediation: products and services receive security fixes while they are within their defined support period. Support periods are determined on a case-by-case basis per product line and published in the official product manual or other official channels.
The following are out of scope: third-party services we do not operate; findings that are already public; reports with no demonstrable security impact; volumetric denial-of-service testing; and social-engineering of our staff or customers.

How to report a vulnerability
Please report potential vulnerabilities through one of the following channels:

  • Email: contact@seer-robotics.ai (preferred).
  • Web form: Coming soon.
  • Telephone: +86 400-762-9969, via our customer service, for those who cannot use a written channel.

We provide more than one channel so that reporters can choose a method that suits them, including by telephone where a written channel is not accessible.

Secure and anonymous reporting
To protect sensitive vulnerability information while it is being exchanged:

  • Our web form is served over HTTPS.

You may report anonymously. If you would like a response, please give us a contact address or an alias.

What to include in your report
To help us validate and fix the issue quickly, please include as much of the following as you can:

  • Product identification - the affected product or service name, the affected version(s), and the platform or environment (OS, hardware) where applicable.
  • Vulnerability description - what the issue is and where it exists, and its type or class (e.g., buffer overflow, SQL injection, improper authentication).
  • Impact - the potential impact if the issue is exploited (confidentiality, integrity or availability), and a severity assessment or CVSS score if you have one.
  • Reproduction steps - step-by-step instructions to reproduce the issue, and proof-of-concept code or technical evidence if available.
  • Discovery information - the date you found the issue and how (testing method, tool, or accidental finding).
  • Your contact information - your name or alias (you may remain anonymous) and a channel for follow-up.
  • Disclosure intent - whether you intend to publish your findings, and any date you are working toward.


What you can expect from us

After you submit a report, we will:

  • acknowledge receipt within 3 business days and assign a tracking reference;
  • aim to triage and validate your report within 7 business days, and contact you if we need more information;
  • keep you informed of our progress at reasonable intervals;
  • aim to deliver a resolution within 90 days, depending on complexity and any third parties involved;
  • notify you when the vulnerability has been remediated, and may invite you to confirm that the fix resolves it.


Coordinated disclosure

We follow a coordinated disclosure approach:

  • We ask that you give us a reasonable opportunity to remediate the issue before disclosing it publicly.
  • We will not publicly disclose details of a reported vulnerability before it has been addressed; any public disclosure will be coordinated and agreed between you and us.
  • We agree an embargo period on a case-by-case basis. Embargo timelines can be adjusted case by case by mutual agreement, including where a coordinator or other vendors are involved.
  • When a fix is released, we publish a security advisory and request a CVE identifier and submit the information to the EU Vulnerability Database (EUVD).


Where to find our security advisories

When a vulnerability has been remediated, we publish a security advisory so that users can assess whether they are affected and how to update. You can find our advisories at:

  • Security advisory page: Coming soon.
  • Machine-readable advisories (CSAF 2.0): To be added.
  • Product release notes and update notifications delivered through the product or its update channel.
  • CVE records (where a CVE has been assigned) and the EU Vulnerability Database (EUVD).

To be notified of new advisories, you can subscribe via [RSS feed / mailing list: Coming soon].

Confidentiality and recognition
We treat vulnerability reports as confidential. We will not share the personal information you provide with third parties without your explicit consent, except where required by law.
With your permission, we are happy to credit you for your discovery in our advisory or on our acknowledgements page. Let us know if you would prefer to remain anonymous.

Safe harbour and good-faith research
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you.
Good-faith research means, among other things, that you:

  • only interact with systems or accounts you own or have explicit permission to test;
  • avoid privacy violations, destruction of data, and any degradation of our services (for example, no denial-of-service testing);
  • access only the minimum data necessary to demonstrate the issue, and do not store, share or use it;
  • give us a reasonable time to resolve the issue before any disclosure.


Policy changes

We may update this policy from time to time. The current version and its publication date are shown in Document control above; material changes are recorded below.
v1.0 — 2026-09-11 — Overseas Products Department— Initial version


Contact Us

For inquiries regarding compliance with the EU Cyber Resilience Act (CRA), vulnerability disclosure, product cybersecurity, or other related matters, please submit your information through our official contact page.

Contact SEER Robotics >

SEER Robotics will route your inquiry to the appropriate team for follow-up and further handling.