One Year On: strengthening IoT Security through Global Certifications and Community Collaboration
One year after launching its Trust Center, Bambu Lab highlights new security certifications, transparency initiatives, and Bug Bounty growth
Someone sits down in the evening, examines our software, discovers a vulnerability we don't yet know about, and reports it instead of exploiting it. That's what a good bug bounty program looks like in practice.
An external researcher approaches the product with fresh eyes, and their report goes directly to our team, improving the products you rely on every day.
Almost one year ago, in October 2025, we launched the Trust Center to make security and privacy part of every stage of our work. Since then, we've earned new certifications, introduced a public security update log, and significantly expanded our Bug Bounty Program.
Today, we're looking back at how far we've come over the past year - with the Bug Bounty Program at the heart of that journey.
The Bug Bounty Program at the core
The Bug Bounty Program (BBP) is our ongoing collaboration with security researchers, white-hat hackers, and professional security organizations from around the world.
The principle is simple: if you discover a vulnerability, report it through the proper channel, and we'll fix it and reward your contribution.
To date, we have worked with over 100 security experts, with single payouts reaching up to $52,000 in rewards. To recognize people helping us strengthen product security, we've launched the Hall of Fame, where we acknowledge researchers who have contributed to the program.
Reports submitted through the BBP are reviewed by our engineering teams and directly contribute to improving our products. Behind those numbers is also a significant change in the way we work. We've redesigned our entire vulnerability management process - from the initial report through remediation and closure, and closely monitor every step to ensure our users' devices remain protected by the latest security updates.
External reviews allow us to see issues we simply couldn't identify from inside the company.
That's exactly why we've built a strong partnership with the security research community, making their contributions an integral part of our product development process.
Making security visible
Security work usually happens behind the scenes, and users rarely notice it. We wanted to change that.That's why we launched the Security Update page, where we will disclose details about specific security patches.
Work that was once invisible will be transparent. Makers will be able to see what has been fixed and when, then get back to focusing on their projects.
We believe transparency is essential for building trust, so we'd rather show the details than ask people to simply take our word for it.
Independent verification through certifications
Security and privacy require independent validation.
We continue to maintain our ISO/IEC 27001, ISO/IEC 27701, and TRUSTe Enterprise Privacy certifications, while adding new compliance milestones over the past year.
- We've implemented the ETSI EN 303 645 standard, which establishes security requirements for IoT devices, including authentication, data protection, and software updates.
Dedicated to global markets, we closely monitor and implement cybersecurity and privacy standards worldwide to ensure a high level of cross-regional compliance:
- Our products also comply with Article 3.3(d) and 3.3(e) of the EU Radio Equipment Directive (RED). This requires us to equip our products with robust wireless security defenses, creating a more trustworthy network environment for users.
- Furthermore, our products meet Australia Cyber Security Act requirements and the UK PSTI regulations, ensuring secure-by-design architecture and rigorous operational standards that deliver reliable, end-to-end security throughout every device's lifecycle."
As a result, our network-connected printers are engineered in accordance with recognized international security standards.
For users, this means robust security measures are seamlessly built into our products and processes, and independently verified against rigorous regulatory frameworks and industry benchmarks.
Security is never finished
Continuous improvements to security are our commitment to making 3D printing both safe and reliable. That commitment is driven by the trust of our community - from individual users who care about their privacy to researchers dedicated to improving cybersecurity.
We'll continue sharing our progress through the Trust Center and remain actively engaged with the security community.
If you discover a vulnerability during your own testing or have feedback on our security architecture, please check the Bug Bounty Program, and contact us at security@bambulab.com.