Support & Service
HOME
Support & Service
Product Security Vulnerability Reporting

Communication and Commitment

In addition to establishing a product security management architecture to ensure the safe and reliable delivery of products, SSSTC is also committed to minimizing network security risks associated with its products.

Thank you for reporting the safety-related issue to SSSTC . Your report helps us improve product safety, and we appreciate your responsible disclosure.

We will confirm the received vulnerability reports as soon as possible and assess and handle them according to the severity and scope of the vulnerability. For vulnerabilities confirmed as significant or actively exploited, our company will notify the relevant authorities and ENISA in accordance with applicable regulations, including the requirements of the EU Cyber Resilience Act (CRA).


Information recommended to be included in the report
To help SSSTC evaluate your submission as quickly as possible, we recommend that you provide the following information:

  • about SSSTC products, including product name, model , and hardware/software version.
  • How, when, and by whom were the potential vulnerabilities discovered?
  • Technical description of the vulnerability, including any relevant (1) known vulnerabilities and (2) existing CVE IDs.
  • Your contact information allows SSSTC to ask necessary follow-up questions.

Send the cryptographic security report using our PGP public key to::psirt@ssstc.com

 

To protect user privacy, data security, and service stability, please ensure that reporters adhere to the following boundaries when verifying vulnerabilities:

  • Only test to the minimum necessary extent to verify vulnerabilities, and avoid unnecessary in-depth probing;
  • Do not damage, tamper with, delete, download or disclose any sensitive or business information that does not belong to you;
  • Do not engage in destructive behaviors such as DoS/DDoS attacks, social engineering, physical attacks, malicious persistence, ransomware, or lateral movement;
  • Do not conduct any tests that may affect the stability of the production environment and service availability;
  • Do not disclose sensitive details to third parties without authorization before completing the closed loop in accordance with this policy.

 

Our processing flow

  • Confirmation: SSSTC will send an email confirming receipt of your report.
  • Initial assessment: Our security team will assess the impact and priorities.
  • Fix and Verification: If effective, we will arrange patching, internal testing, and external verification. Multiple rounds of communication may be required.
  • Disclosure (if applicable): Following mitigation measures, the SSSTC may issue announcements, CVE IDs, and technical details in accordance with our responsible disclosure policy.

 

Responsible Disclosure and Safe Harbor Statement
To encourage responsible whistleblowing, we pledge not to take legal action or notify law enforcement agencies against whistleblowers who adhere to the above principles (unless other illegal activities are involved):

  • Only test the systems and resources you are authorized to access.
  • To avoid unnecessary interruptions to the production system or data corruption.
  • Collect only the minimum necessary data for copying; avoid downloading sensitive user data.
  • Unless both parties agree, vulnerability details or proof-of-concept (PoC) should not be disclosed before a fix is achieved.
  • Please stop testing immediately if we request it.

This safe harbor does not apply to malicious or criminal acts such as fraud, extortion, or data theft.Cyber Resilience Act(CRA)

Inquiry

total 0 items

Compare list

Select up to 4 products to compare.