Vulnerability Reporting Channels
If you discover a security vulnerability in products under imoo and its affiliated brands, please report the potential security vulnerability in imoo products to us by email at psirt@imoo.com. If suppliers are involved, we will notify them of the vulnerability information immediately.
Given the sensitive nature of vulnerability information, we kindly request all email reports to be encrypted using our PGP public key(fingerprint: 67C791DCA6876316134E57D67BED0601909848A6).
You may also contact us through WhatsApp at +65 8858 9557.
What to Include in Your Report
To help us better confirm potential vulnerabilities, your email should include, without limitation, the following information:
- The reporter's name/organisation name and contact details.(voluntarily provided)
- The affected product/service and its version information.
- A detailed description of the potential vulnerability, such as the vulnerability name, severity level, type, details, proof of vulnerability and remediation recommendations.
- Proof-of-exploit information for the potential vulnerability.
- Information on whether the vulnerability has been publicly exploited, if any.
Pre-submission Notes and Effectiveness of This Agreement
Before formally submitting a vulnerability, please read the content of this page in full and fully understand the relevant standards of rights, responsibilities and obligations for disclosure.
If you do not agree to any terms of this programme, please stop using this reporting channel immediately, and we will no longer accept the security report you submit. If you have completed the vulnerability submission, this indicates that you have read in full, fully understood and voluntarily accepted all binding terms and relevant requirements set out below.
Vulnerability Communication and Confidentiality Rules
After receiving your vulnerability report, we will immediately confirm the details. Where the vulnerability is verified as genuine, we will proactively contact you within 7 working days of receiving the report. If our review determines that the vulnerability is not valid, we will not provide further feedback.
Please understand that, due to factors such as the vulnerability risk level and verification difficulty, the actual handling timeframes and the form of our responses may vary.
To protect user safety to the greatest extent possible, before completing vulnerability verification and releasing a remediation patch, imoo will not disclose, discuss or confirm the relevant security vulnerability externally. We may set different confidentiality periods depending on the vulnerability.
Code of Conduct for Reporting
By submitting a vulnerability report to imoo, you undertake to make the following commitments and to strictly comply with them:
- Before imoo has completed vulnerability verification, risk classification, patch development and version rollout, you must not forward, disseminate or publicly release any details relating to the vulnerability to any third party.
- Without imoo's written permission, you must not disclose vulnerability information externally without authorisation. Otherwise, this will be deemed a breach of all terms of this disclosure programme.
- You must not exploit any discovered vulnerability to carry out any harmful acts.
- All vulnerability discovery and security testing activities must comply with the laws, regulations and regulatory requirements of all relevant jurisdictions.
- You have read in full and agree to the Privacy Policy on the official imoo website and all rules of this vulnerability disclosure programme.
You can review the official imoo Privacy Policy before submitting a report.
Additional Terms and Authorisation Provisions
- During testing, whether you intentionally or unintentionally obtain data relating to imoo, affiliated brands, and corporate internal customers, employees or business operations, you must not store, record, use or disclose such data to any third party. All such access must be truthfully stated in the vulnerability report.
- By submitting a vulnerability report to imoo, you grant us a worldwide, perpetual, royalty-free and non-exclusive licence. imoo is entitled to use all content of the report you submit for the purpose of remediating security vulnerabilities in the products and services of itself and its affiliates.
- Before submitting a vulnerability report, please confirm that you have never disclosed any content relating to the vulnerability to any entity other than imoo.

