我們以 ISO 29147、ISO 30111 與 EU Cyber Resilience Act 為基準,建立透明、可預測的漏洞協調揭露流程。
Built on ISO 29147, ISO 30111 and the EU Cyber Resilience Act, our coordinated vulnerability disclosure process is transparent and predictable.
集佳股份有限公司重視產品安全。我們歡迎安全研究人員、客戶與合作夥伴,以善意通報產品中發現的潛在漏洞。
GIGA-TMS INC. takes product security seriously. We welcome good-faith reports of potential vulnerabilities from security researchers, customers, and partners.
3 個工作天是我們對通報者的初步回覆目標,不是安全或法規風險判斷的等待期。收到通報後,我們會立即進行初步分析;如有需要,將依通報程序啟動加速處理。
Our 3-business-day target is for an initial acknowledgement, not a waiting period for security or regulatory risk decisions. We begin an initial assessment upon receipt and accelerate handling when required.
本政策遵循 ISO/IEC 29147(漏洞揭露)、ISO/IEC 30111(漏洞處理)與 EU Cyber Resilience Act 之要求,確保流程透明、可預測、對善意研究者友善。
This policy follows ISO/IEC 29147 (vulnerability disclosure), ISO/IEC 30111 (vulnerability handling) and the EU Cyber Resilience Act, keeping the process transparent, predictable and researcher-friendly.
我們視安全研究社群為提升產品安全的重要夥伴,並對遵循本政策之通報者提供安全港承諾。
We consider the security research community a key partner in improving product security, and offer a safe-harbor commitment to reporters who follow this policy.
本網站為純靜態漏洞通報網站;請僅以電子郵件通報。本網站不提供線上表單、檔案上傳、資料傳送、帳號登入或案件查詢功能。
This is a static vulnerability reporting site. Please report by email only; the site provides no online submission form, file upload, data transfer, account login, or case-tracking function.
[Vulnerability Report],並依第 03 節的電子郵件通報指引提供必要摘要。[Vulnerability Report] and follow the email reporting guide in Section 03.本頁僅提供靜態通報指引與郵件範本,不會蒐集、傳送或儲存任何資料。請在您的郵件應用程式中建立並寄送通報。
This page provides a static reporting guide and email template only. It does not collect, transmit, or store any information; create and send the report from your own email client.
請在您的郵件應用程式中撰寫通報;本網站不接收或處理任何輸入內容。
[Vulnerability Report]。[URGENT Security Report]。這僅用於協助優先分流,不代表固定公開時限或修補承諾。[URGENT Security Report] to help prioritise triage; it is not a fixed disclosure or remediation SLA.請複製下列範本至您的郵件應用程式後填寫。
Copy this static template into your own email client and complete it there.
僅供通報時參考選填。選擇「其他」或留空亦可,我們將於收件時協助歸類。
For reference only when reporting. Choose "Other" or leave it blank — we will help classify it on receipt.
我們以風險、可利用性、技術複雜度與協調需求決定處理優先順序;除初步回覆目標外,不承諾固定修補或揭露天數。
We prioritise handling according to risk, exploitability, technical complexity, and coordination needs. Apart from the initial acknowledgement target, we do not commit to fixed remediation or disclosure dates.
研究者通報線與法定通報線是兩條不同且可並行的流程。「3 個工作天」僅為回覆研究者的初步回覆目標,並不延後或取代法規風險判斷。若本公司知悉產品存在正被主動利用的漏洞,或知悉發生影響產品安全的嚴重事件,將不延遲地依適用之 CRA Article 14 流程,透過 EU 單一通報平台向協調 CSIRT 通報,並使 ENISA 同時可取得通報資訊。
Researcher communication and statutory reporting are separate and may run in parallel. The 3-business-day target concerns acknowledgement to the reporter only; it does not delay or replace regulatory risk decisions. Where the manufacturer becomes aware of an actively exploited vulnerability or a severe security incident, the applicable CRA Article 14 process is triggered through the EU single reporting platform to the coordinating CSIRT, with ENISA simultaneously able to access the notification.
自本公司知悉起,最遲 24 小時內提出早期預警;最遲 72 小時內提出漏洞通報;修補或緩解措施可用後最遲 14 日提出最終報告。
Actively exploited vulnerability: early warning within 24 hours of awareness; vulnerability notification within 72 hours; final report within 14 days after a corrective or mitigating measure becomes available.自本公司知悉起,最遲 24 小時內提出早期預警;最遲 72 小時內提出事件通報;自 72 小時事件通報後一個月內提出最終報告。
Severe security incident: early warning within 24 hours of awareness; incident notification within 72 hours; final report within one month after the incident notification.明確界定受理與非屬本政策範圍之標的,避免混淆。
To avoid confusion, this section clearly defines what is and isn't covered by this policy.
對於遵循本政策、以善意進行研究與通報之人員,本公司承諾不採取法律行動。我們視安全研究社群為提升產品安全的重要夥伴。經通報者同意,我們將於安全公告中公開致謝。
For anyone researching and reporting in good faith under this policy, we commit to taking no legal action. We view the security research community as a key partner in improving product security, and, with the reporter's consent, will credit them publicly in the advisory.