Coordinated Vulnerability Disclosure · v2.2

Product Security.
Built on trust.

我們以 ISO 29147、ISO 30111 與 EU Cyber Resilience Act 為基準,建立透明、可預測的漏洞協調揭露流程。每一份善意通報,都是讓產品更安全的力量。

Built on ISO 29147, ISO 30111 and the EU Cyber Resilience Act, our coordinated vulnerability disclosure process is transparent and predictable — every good-faith report helps make our products safer.

Version 2.2Policy
ISO 29147 · 30111Standards
EU CRACompliance
48 hrsResponse SLA
01 · Our Commitment

政策聲明

Policy Statement

集佳科技重視產品安全。我們歡迎安全研究人員、客戶與合作夥伴,以善意通報產品中發現的潛在漏洞。

GIGA-TMS takes product security seriously. We welcome good-faith reports of potential vulnerabilities from security researchers, customers, and partners.

對於每一件通報,我們承諾於 48 小時內提供初步回覆與案件編號(CVD-YYYY-NNN),並依本政策所述時程進行驗證、修補與協調揭露。

For every report, we commit to an initial reply within 48 hours together with a case number (CVD-YYYY-NNN), followed by verification, remediation and coordinated disclosure per the timeline in this policy.

本政策遵循 ISO/IEC 29147(漏洞揭露)、ISO/IEC 30111(漏洞處理)與 EU Cyber Resilience Act 之要求,確保流程透明、可預測、對善意研究者友善。

This policy follows ISO/IEC 29147 (vulnerability disclosure), ISO/IEC 30111 (vulnerability handling) and the EU Cyber Resilience Act, keeping the process transparent, predictable and researcher-friendly.

我們視安全研究社群為提升產品安全的重要夥伴,並對遵循本政策之通報者提供安全港承諾。

We consider the security research community a key partner in improving product security, and offer a safe-harbor commitment to reporters who follow this policy.

48h
初步回覆 SLAAcknowledgement SLA
90d
重大漏洞修補目標Critical Fix Target
100%
善意通報安全港Good-Faith Safe Harbor
02 · How to Report

通報管道

How to Report

含技術細節之通報,建議使用 PGP 公鑰加密;一般性回報可直接寄送。

For reports containing technical detail, please encrypt with our PGP key; general inquiries can be sent directly.

Report Email
主旨請標註 [Vulnerability Report],並儘可能使用第 03 節之範本。
Please use the subject [Vulnerability Report] and, where possible, the template in Section 03.

PGP Public Key

強烈建議以 PGP 加密技術細節與 PoC。
We strongly recommend encrypting technical details and PoC with PGP.
Fingerprint: XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX
03 · Report Template

通報範本

Report Template

本頁面為純靜態頁面,不蒐集、不傳送任何資料。填寫後可一鍵複製或開啟郵件應用程式。

This is a purely static page — nothing is collected or transmitted. Once filled in, copy the report with one click or open it directly in your mail app.

填寫通報資料 Fill in Report

所有欄位皆存在於您的裝置上,送出前不會離開瀏覽器。
All fields stay on your device — nothing leaves your browser until you send it.
於安全公告中公開致謝 / Credit me in the advisory
已複製至剪貼簿 · Copied to clipboard

即時預覽 Live Preview

您所填寫的內容將即時組合成下列通報信件格式。
What you enter is assembled live into the report format below.

Preview
04 · Category Reference

分類參考

Category Reference

僅供通報時參考選填。選擇「其他」或留空亦可,我們將於收件時協助歸類。

For reference only when reporting. Choose "Other" or leave it blank — we will help classify it on receipt.

05 · Handling Timeline

處理時程

Handling Timeline

從收件到揭露,每一步都有明確時程承諾。

From intake to disclosure, every step carries a clear time commitment.

初步回覆
Acknowledgement
≤ 48 小時
回覆案件編號(CVD-YYYY-NNN),確認已受理並指派窗口。
We reply with a case number (CVD-YYYY-NNN), confirming intake and an assigned contact.
驗證與定級
Triage
數個工作天
重現漏洞、CVSS 評估、影響範圍比對,並與通報者保持溝通。
We reproduce the issue, score it with CVSS, check its impact, and stay in touch with the reporter.
修補
Remediation
45 / 90 天
依嚴重度目標時程開發並發布修補,重大漏洞以 45 天為目標。
Fixes are developed and released against severity-based targets, aiming for 45 days on critical issues.
協調揭露
Disclosure
修補後
發布安全公告;如通報者需要,協助申請 CVE ID,並公開致謝。
We publish a security advisory, help with a CVE ID if requested, and credit the reporter publicly.
06 · Scope

適用範圍

Scope

明確界定受理與非屬本政策範圍之標的,避免混淆。

To avoid confusion, this section clearly defines what is and isn't covered by this policy.

受理範圍 In Scope

  • Promag 品牌硬體產品及其韌體Promag-branded hardware products and their firmware
  • 產品隨附之設定工具與 SDKCompanion configuration tools and SDKs
  • 產品之網路服務與管理介面Product network services and management interfaces

非本政策範圍 Out of Scope

  • 公司網站與行銷基礎設施(仍受理,轉交 IT)Corporate website / marketing infrastructure (still accepted, routed to IT)
  • 對產品或服務之阻斷式測試(DoS)Denial-of-service testing against products or services
  • 社交工程、實體入侵測試Social engineering or physical intrusion testing
07 · Safe Harbor

安全港聲明

Safe Harbor Statement

對於遵循本政策、以善意進行研究與通報之人員,本公司承諾不採取法律行動。我們視安全研究社群為提升產品安全的重要夥伴。經通報者同意,我們將於安全公告中公開致謝。

For anyone researching and reporting in good faith under this policy, we commit to taking no legal action. We view the security research community as a key partner in improving product security, and, with the reporter's consent, will credit them publicly in the advisory.