Product Security and Coordinated Vulnerability Disclosure Policy
Product security is an important responsibility at Insta360. We welcome good-faith reports from security researchers, customers, partners and the public concerning potential security vulnerabilities in Insta360 products and services, and seek to protect users through coordinated vulnerability disclosure.
Policy version: A/0
Vulnerability contact: SRC@insta360.com
1. Scope
We accept reports of any potential security vulnerability reasonably related to Insta360 products or services.
The product security support commitments in this policy primarily apply to products with digital elements sold in the European Union, including related hardware, firmware, software, mobile applications and cloud services, as well as third-party component issues that have a verifiable security impact in Insta360's actual use environment.
Products that have reached the end of security support are no longer subject to the remediation timelines stated in this policy. We will still receive and assess relevant reports and will fullfil applicable legal obligations. If you are unsure whether an issue is in scope, contact us using the email address on this page.
2. How to report a vulnerability
Send vulnerability reports to SRC@insta360.com.
For sensitive reports: email SRC@insta360.com with the subject “PGP KEY REQUEST”. We will provide the current PGP public key and fingerprint by email. Please do not include sensitive technical details in the initial request.
Recommended report contents:
- The affected product name, model, software or firmware version, and any relevant URL.
- The vulnerability type, detailed description, potential impact and realistic attack scenario.
- The test environment, tools, parameters and complete reproduction steps.
- Necessary logs, network captures, screenshots, video or a minimal proof of concept.
- A CVSS score or severity recommendation, where available.
- Your contact details, anonymity preference and proposed disclosure plan.
Do not include real user data that is unrelated to vulnerability validation.
3. Good-faith research
Research that follows this policy and applicable law and avoids harm to users and services will be treated as good-faith security research. If you are unsure whether a test is outside the scope of this policy, contact us before continuing.
Researchers must use only devices, accounts and data that they own or are expressly authorised to use; stop further exploitation after confirming a vulnerability; limit data access to the minimum necessary to demonstrate the vulnerability; and keep vulnerability information confidential until remediation and coordinated disclosure are complete.
Do not modify, delete or download unrelated data. Do not perform denial-of-service or stress testing. Do not install backdoors, maintain persistent access or move laterally. Do not conduct social engineering, phishing, spam or physical attacks, or engage in any activity that infringes privacy or intellectual property rights or violates applicable law.
4. Vulnerability handling process
Receipt. We will acknowledge receipt within 5 business days and provide a unique tracking number, an expected time for the initial assessment and contact details for the vulnerability coordinator.
Verification. Within 7 business days after acknowledgement, we will complete initial technical verification and risk assessment. If information is insufficient, we will ask the reporter for additional logs, reproduction steps or a proof of concept.
Remediation. We will identify affected products, components and versions, use CVSS v4.0, exploitability and actual impact to determine priority, and develop a fix or mitigation.
Release. After the remediation is validated and a secure update path is available, we will release a security update or mitigation guidance without undue delay and explain any action users need to take.
Coordinated disclosure. We will coordinate the disclosure date, advisory content and any confidentiality period needed to protect users with the reporter, and notify the reporter when remediation is complete.
5. Target remediation timelines
- Critical or High, CVSS v4.0 score 7.0 or above: target a fix or effective mitigation within 30 days.
- Medium, CVSS v4.0 score 4.0 to 6.9: target completion within 60 days.
- Low, CVSS v4.0 score below 4.0: target completion within 90 days.
Complex hardware dependencies, supply-chain coordination or other exceptional circumstances may affect these targets. If a delay occurs, we will explain the revised expected timeline and any available interim mitigation to the reporter.
6. Coordinated disclosure and confidentiality
We aim to complete coordinated disclosure within 90 calendar days after a vulnerability is confirmed and will coordinate the disclosure date, advisory content and any necessary confidentiality period with the reporter. If the target cannot be met, we will explain the reason and coordinate a revised timeline.
Where necessary to protect users or fulfil legal obligations, Insta360 may report basic vulnerability information earlier and may submit required information to competent authorities, a CSIRT or ENISA in accordance with applicable law.
Unless otherwise required by law, we will not share a reporter's personal information with unrelated third parties without explicit consent. Reports may be submitted anonymously, although anonymity may limit follow-up communication and public acknowledgement.
7. Recognition
Researchers who follow this policy and responsibly disclose a valid vulnerability may, with their consent, receive public acknowledgement or, at Insta360's discretion, non-cash recognition such as a commemorative item.
Any recognition is entirely discretionary and is conditional on compliance with this policy. Reports that violate this policy are not eligible for recognition.












































