Welcome to the Vulnerability Disclosure and Response Program (hereinafter referred to as “the Program”) established by Shenzhen EN+ Technology Co., Ltd. and its affiliates (hereinafter referred to as “EN+” or “we”).
We value the network security of our products and business systems and highly recognize the contributions of security researchers to the industry ecosystem. We welcome you to submit security vulnerabilities related to EN+ products and services. Before joining the Program and submitting vulnerabilities, please read and fully understand this “EN+ Vulnerability Disclosure and Response Agreement” (hereinafter referred to as “this Agreement”). By submitting a vulnerability report, you are deemed to have read, understood, and agreed to abide by this Agreement and the EN+ Privacy Policy (Link: [To be supplemented URL]).
1.1 This Agreement is a legally binding document entered into between you (the “Reporter”) and EN+ concerning your participation in the Program.
1.2 Reporter refers to any natural person, legal person, or other organization submitting vulnerabilities through designated EN+ channels.
1.3 This Agreement includes rules, supplementary agreements, and explanatory documents published by EN+ from time to time, all of which have the same legal effect as this Agreement.
2.1 Reporters shall submit vulnerabilities through the designated platform (www.en-plustech.com) and according to the provided guidelines.
2.2 Vulnerability reports should include:
2.3 Acceptable scope includes:
2.4 The following are not accepted:
2.5 Vulnerability rating considers factors including:
2.6 Vulnerability disclosure principles:
2.7 Reporters must ensure submitted materials are truthful and lawful and must not cause risks due to false information.
2.8 Reference remediation timelines:
3.1 Reporters must comply with laws, regulations, and this Agreement, and must not damage EN+ systems or infringe upon user rights.
3.2 Do not obtain vulnerabilities through illegal means such as scanning, sniffing, brute-forcing, or phishing.
3.3 The following behaviors are prohibited:
3.4 Reporters must ensure the report content is truthful and complete.
3.5 After submission, do not threaten to publicly disclose the vulnerability, nor transfer or authorize a third party to use or disclose it.
3.6 All intellectual property rights to the vulnerability report and its results belong to EN+.
3.7 The Reporter has a strict duty of confidentiality regarding any EN+ information accessed during participation.
3.8 Minors (under 18 years old) must participate under the guidance of a guardian.
4.1 EN+ is responsible for maintaining the normal operation of the vulnerability submission process.
4.2 EN+ has the right to independently verify, rate, and decide on remediation measures.
4.3 EN+ will promptly follow up on valid reports and provide feedback on handling opinions within a reasonable timeframe.
4.4 EN+ protects Reporter’s personal information in accordance with the law.
4.5 For malicious, illegal, or misleading reports, EN+ has the right to terminate participation and pursue accountability.
4.6 EN+ has the right to adjust or terminate the Program and will notify via announcement or email.
4.7 EN+’s review does not exempt the Reporter from responsibility for the legality of submitted content.
4.8 Disputes between the Reporter and any third party must be handled by the Reporter. If EN+ suffers damage as a result, the Reporter shall bear liability for compensation.
5.1 Report content should be complete, accurate, and reproducible, including:
5.2 Vulnerability rating considers factors including:
5.3 Do not disclose vulnerabilities to any third party without written consent from EN+.
5.4 When disclosure is approved, ensure:
5.5 Ownership of the vulnerability report and its results belongs to EN+; use, publication, or transfer without authorization is prohibited.
6.1 All vulnerability reports, testing materials, and related submissions provided by the Reporter shall become the property of EN+.
6.2 Without prior written permission from EN+, the Reporter shall not copy, distribute, disclose, or otherwise use any such materials.
6.3 In the event of any violation of this section, EN+ reserves the right to revoke the Reporter’s eligibility and pursue legal liability in accordance with applicable laws.
6.4 Personal information submitted by the Reporter shall be used solely for identity verification, vulnerability handling, and statistical purposes.
6.5 EN+ shall adopt reasonable technical and organizational measures to protect the security of such information.
6.6 The Reporter shall ensure that all personal information provided is true, accurate, and valid. Any consequences arising from false or invalid information shall be borne by the Reporter.
7.1 EN+ may suspend or terminate the Program based on business, technical, or security reasons, and the Reporter may not claim compensation for this.
7.2 EN+ may immediately disqualify a Reporter and pursue accountability if any of the following occur:
7.3 EN+ is not liable for service unavailability caused by:
7.4 EN+ does not guarantee that the platform is vulnerability-free or continuously available.
7.5 After a Reporter exits the Program, EN+ has the right to delete all their data and is not obligated to provide export services.
8.1 This Agreement is governed by the current laws and regulations of the People’s Republic of China (excluding conflict of laws provisions).
8.2 Disputes should be resolved through negotiation; if negotiation fails, they shall be submitted to the People’s Court located at EN+’s location (Nanshan District, Shenzhen City) for handling.
8.3 If any clause is invalid, it does not affect the validity of the remaining clauses.
8.4 Section headings are for convenience only and do not affect interpretation.
8.5 Your continued participation in the Program constitutes acceptance of the updated terms.
For questions, complaints, or suggestions, please contact:
Email: support@en-plus.com.cn
Address: 2nd Floor, Building 6, No. 1026 Songbai Road, Nanshan District, Shenzhen City, Guangdong Province, China
Get the latest news from EN Plus
Floor 2-3, Building 6, No.1026 Songbai Road, Nanshan District, Shenzhen, China, 518055