KOB Tech Power for Life & Care

KOB Tech Corporation ("we," "our," or "the Company") is continuously committed to the security of our battery storage products and related services, including our remote-monitoring cloud and management application (collectively, "the Products"). This page describes our vulnerability disclosure policy and provides security information for using the Products safely.

Vulnerability Disclosure Policy

Article 1 (Reporting Contact)

If you discover a vulnerability in the Products, please report it to the contact below. Anonymous reports are accepted.

Email: info@kob-tech.com (please include "Vulnerability Report" in the subject line)
Address: Toseki Bldg. 12F, 4-9-3 Nihonbashi-Honcho, Chuo-ku, Tokyo 103-0023, Japan
Company: KOB Tech Corporation

Where possible, please include the following in your report:

  1. The affected product and version (model number or serial number for hardware; URL for web services)
  2. A description of the vulnerability and steps to reproduce it
  3. The expected impact
  4. Your contact information (optional)

Article 2 (Handling of Reports)

  1. We will acknowledge receipt of your report within 5 business days.
  2. We will investigate the report and determine its severity (with reference to CVSS and similar standards) and our response plan.
  3. We will implement fixes or mitigations with a priority appropriate to the severity.

Article 3 (Status Updates)

  1. We will update the reporter on the progress of our investigation and response approximately every 30 days.
  2. When a vulnerability has been resolved, we will inform the reporter of the fix, the affected versions, and how the fix is applied, and will notify users via this website or other channels where users are affected.

Article 4 (Requests to Reporters)

  1. Please verify vulnerabilities only on devices and accounts that you own or are authorized to use.
  2. Please refrain from accessing third-party data or performing actions that disrupt service (such as DoS attacks).
  3. Please refrain from publicly disclosing vulnerability information until a fix is complete and we have made an announcement (coordinated vulnerability disclosure).
  4. We also accept reports made under IPA's Information Security Early Warning Partnership framework (via IPA's vulnerability reporting desk).

Using the Products Safely

Article 5 (Secure Setup)

  1. The Products' remote monitoring connects only to our servers as configured at the factory. No server configuration is required on your side.
  2. When connecting a device to your home Wi-Fi, use a Wi-Fi network protected with WPA2 or higher. Do not connect to unencrypted (passwordless) Wi-Fi networks.
  3. If you use the management application (for distributors and administrators), be sure to change the issued initial password after your first login (8 characters or more). Do not reuse passwords across services or share them with third parties.
  4. The product model number can be found on the label on the unit or on the device information screen of the management application.

Article 6 (Software Updates)

  1. Device firmware updates are performed remotely by the Company and the manufacturer. No action is required on your part. Please keep the device powered on and connected to the network so updates can be applied.
  2. When a security-related update is released, we will announce its content, necessity, and the expected impact of not applying it via this website or through distributors.
  3. The management application is always delivered in its latest version; simply opening it in your browser applies the latest version.

Article 7 (Disclaimer When Updates Are Not Applied)

We are not liable for accidents, failures, or information leaks that occur while our security updates cannot be applied due to circumstances on your side, such as the device being disconnected from the network for an extended period. Please keep the device connected to the network at all times.

Article 8 (Support Period)

  1. We continue to provide security support (vulnerability fixes) for the Products after their sale has ended.
  2. If we end security support, we will announce it at least 12 months before the end date via this website and through distributors.
  3. After support ends, vulnerability fixes will no longer be provided. Please understand the risks of continued use and consider upgrading to a successor product.

Article 9 (Data Erasure on Disposal or Transfer)

Devices store configuration information such as Wi-Fi credentials. If a device is disposed of or resold without erasing this data, it could be obtained by third parties. Before disposal, transfer, or return, be sure to do the following:

  1. Perform a factory reset on the device to erase your configuration information, including Wi-Fi settings. Refer to the instruction manual or contact your distributor for the procedure.
  2. Notify your distributor or our contact desk of the disposal or transfer. We will deactivate the device's server registration, stop collecting monitoring data, and delete the stored data.

Article 10 (Changes to This Page)

The content of this page may change without notice in response to product specification changes or security developments. Revised content takes effect when posted on this website.

Established: July 8, 2026

We also accept inquiries directly by phone or email.