ESMUDisplay Control Module
Product details and the guidance you need to deploy, maintain, and support your system.
Discuss your projectDisclosure policy
Version: 1.0
Effective Date: October 14, 2025
1. Purpose
INTELLIGENT ENERGY CONTROL ("IEC") is committed to maintaining the security, reliability, and integrity of its products and services.
This Vulnerability Disclosure Policy provides a coordinated process for customers, partners, security researchers, and other stakeholders to report potential security vulnerabilities affecting IEC products and services. IEC welcomes responsible vulnerability reports and will work with reporters to investigate, validate, and remediate legitimate security issues.
2. Scope
This policy applies to IEC Battery Management System (BMS) products, including associated firmware and software developed and maintained by IEC. Third-party products, services, and software not developed or maintained by IEC are outside the scope of this policy.
3. Reporting a Vulnerability
Security vulnerabilities may be reported through the following channels:
Security Contact
security@iecbms.com
Alternative Contact
info@iecbms.com
When submitting a report, please include:
- Product name
- Product version
- Detailed description of the vulnerability
- Potential impact
- Steps required to reproduce the issue
- Supporting evidence (logs, screenshots, proof-of-concept, etc.)
4. Response Process
- IEC will acknowledge receipt of vulnerability reports within 7 business days.
- Review and validate reported vulnerabilities.
- Request additional information when necessary.
- Provide status updates during the investigation process when appropriate.
- Prioritize remediation based on severity and potential impact.
5. Vulnerability Handling
Once a vulnerability is confirmed, IEC will assess the affected products and determine the appropriate remediation actions.
- Develop and validate corrective actions.
- Release security updates as appropriate.
- Provide mitigation guidance when required.
- Notify affected customers when necessary.
6. Coordinated Disclosure
IEC supports coordinated vulnerability disclosure and encourages responsible reporting. IEC will work collaboratively with reporters to determine an appropriate disclosure timeline.
We request that reporters maintain confidentiality until remediation or mitigation measures become available.
7. Safe Research Guidelines
- Act in good faith.
- Avoid disrupting products, systems, or services.
- Avoid unauthorized access, modification, or disclosure of data.
- Comply with applicable laws and regulations.
8. Security Advisories
When appropriate, IEC may publish Security Advisories containing:
- Advisory ID
- Publication date
- Affected products and versions
- Vulnerability description
- Severity information
- Mitigation recommendations
- Corrected versions and upgrade guidance
Published advisories are available in the Security advisories tab.
9. Policy Updates
IEC may update this policy periodically to reflect changes in products, services, security practices, or regulatory requirements.
The latest version is available here.
