Security Response
Hai Robotics Product Security Incident Response Team, PSIRT, is dedicated to protecting product and system security across the full lifecycle, from development to deployment. We follow globally recognized security practices and responsible vulnerability disclosure principles. We also work with security researchers, customers, and partners to help identify, assess, and address potential security risks in a timely manner.
Structured Response Process
Detection & Intake
Multiple reporting and monitoring channels:
Security issues may be identified through customer feedback, global support channels, 24/7 system monitoring, and internal security reviews.
Initial response within 24 hours:
Our dedicated security team reviews incoming reports and performs an initial assessment within 24 hours.
Assessment & Prioritization
Risk-based classification:
We assess security issues with reference to CVSS scoring, while also considering product context, business impact, exploitability, and affected scope.
Impact analysis:
We identify affected products, versions, deployment scenarios, and potential attack paths to determine the appropriate response priority.
Remediation & Verification
Timely mitigation and remediation:
Depending on the issue, we may apply code hardening, configuration updates, security policy changes, temporary mitigations, or software patches to reduce risk as quickly as possible.
Verification before closure:
Remediation measures are validated through security testing, regression checks, and, where appropriate, follow-up penetration testing to confirm that the risk has been effectively addressed.
Communication & Guidance
Security advisories:
When appropriate, we publish security advisories to communicate relevant updates, remediation status, and recommended actions.
Customer guidance:
We provide security recommendations to help customers optimize system configuration, reduce exposure, and strengthen operational security.
Core Principles
- Priority Response: High-risk vulnerabilities are escalated through a fast-track response process, with dedicated engineering resources assigned as a priority.
- Risk Containment: We follow a risk containment approach to minimize potential impact while maintaining business continuity during remediation.
- Responsible Collaboration: We respect the privacy of vulnerability reporters and support responsible disclosure to help build a healthier security ecosystem.
Security Advisories
We publish product security updates on an ongoing basis, including vulnerability fixes, system improvements, and risk notifications.
These advisories help customers stay informed about product security status, recommended actions, and the progress of security improvements.
Security Advisory (2026.05.18) Learn More
Security Advisory (2026.05.27) Learn More
Security Advisory (2026.06.08) Learn More
Report a Security Issue
If you discover a potential security vulnerability, abnormal system behavior, or security-related risk when using our products or systems, please report it through our official security reporting channel.
All valid reports will be reviewed, assessed, and handled through our security response process.