DATE: 2026/09/11
SEER Robotics Advances EU CRA Compliance with Launch of Coordinated Vulnerability Disclosure Policy
As of September 11, 2026, the vulnerability and serious security incident reporting obligations under the EU Cyber Resilience Act (CRA) officially take effect, requiring manufacturers to establish mechanisms for vulnerability receipt, analysis, and reporting. The main CRA requirements will be fully applicable from December 2027.
In alignment with this regulatory milestone, SEER Robotics has published its Coordinated Vulnerability Disclosure (CVD) Policy, opening vulnerability reporting channels to security researchers, customers, and the public. The policy defines clear timelines and responsibilities across the full vulnerability lifecycle — receipt, validation and triage, remediation delivery, and coordinated disclosure.
This publication marks a key milestone in SEER Robotics' EU CRA compliance journey and establishes a transparent, traceable security collaboration framework for customers and partners worldwide.
Coordinated Vulnerability Disclosure Policy
Document control
Document owner: Overseas Products Department
Version: 1.0
Published date: 2026-09-11
Public location: Coming soon
Classification: Public
Introduction
Shanghai Seer Intelligent Technology Co., Ltd. ("we", "us") is committed to the security of our products and the people who rely on them. We welcome reports of potential security vulnerabilities from security researchers, customers and members of the public. This Coordinated Vulnerability Disclosure (CVD) policy explains what is in scope, how to report a vulnerability to us, how we will respond, and how we coordinate public disclosure.
Scope
This policy applies to all products and services of Shanghai Seer Intelligent Technology Co., Ltd., including but not limited to SRC series robot controllers, self-developed AMRs and mobile robots, charging stations, scheduling systems and other products with network communication capabilities.
Eligibility for remediation: products and services receive security fixes while they are within their defined support period. Support periods are determined on a case-by-case basis per product line and published in the official product manual or other official channels.
The following are out of scope: third-party services we do not operate; findings that are already public; reports with no demonstrable security impact; volumetric denial-of-service testing; and social-engineering of our staff or customers.
How to report a vulnerability
Please report potential vulnerabilities through one of the following channels:
We provide more than one channel so that reporters can choose a method that suits them, including by telephone where a written channel is not accessible.
Secure and anonymous reporting
To protect sensitive vulnerability information while it is being exchanged:
You may report anonymously. If you would like a response, please give us a contact address or an alias.
What to include in your report
To help us validate and fix the issue quickly, please include as much of the following as you can:
What you can expect from us
After you submit a report, we will:
Coordinated disclosure
We follow a coordinated disclosure approach:
Where to find our security advisories
When a vulnerability has been remediated, we publish a security advisory so that users can assess whether they are affected and how to update. You can find our advisories at:
To be notified of new advisories, you can subscribe via [RSS feed / mailing list: Coming soon].
Confidentiality and recognition
We treat vulnerability reports as confidential. We will not share the personal information you provide with third parties without your explicit consent, except where required by law.
With your permission, we are happy to credit you for your discovery in our advisory or on our acknowledgements page. Let us know if you would prefer to remain anonymous.
Safe harbour and good-faith research
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you.
Good-faith research means, among other things, that you:
Policy changes
We may update this policy from time to time. The current version and its publication date are shown in Document control above; material changes are recorded below.
v1.0 — 2026-09-11 — Overseas Products Department— Initial version
Contact Us
For inquiries regarding compliance with the EU Cyber Resilience Act (CRA), vulnerability disclosure, product cybersecurity, or other related matters, please submit your information through our official contact page.
SEER Robotics will route your inquiry to the appropriate team for follow-up and further handling.