This website uses essential and analytics cookies. You can choose your option by clicking “Accept All” or “Accept Essential” as Cookies Preferences. For more detailed information about the cookies we use, see our Cookie Policy.
MiTAC Corporation
Coordinated Vulnerability Disclosure Policy
Purpose
MiTAC Digital Technology Corporation (MiTAC) welcomes good-faith reports of potential security or privacy vulnerabilities affecting MiTAC products, systems, or services. This policy explains how to report an issue and how MiTAC coordinates assessment, remediation, and disclosure. Unsupported products, third-party assets, and activities without authorization may be outside scope, but reports may still be reviewed based on risk and MiTAC’s responsibility.
Identification/contact
Policy Version: 1.1
Effective Date: [2026-09-10]
Last Updated:[2026-09-10]
Revision History:
| Revision | Revision date | Note |
| 1.1 | 2026/9/10 | First issue |
Policy Owner:Jaster
Scope/covered products
This policy applies to the supported MiTAC products, versions, and services listed at [https://www.mitacmdt.com/en/contacts/cra-cvd-policy], including the identified versions, components, environments, and support conditions. Unsupported products and third-party assets not owned or controlled by MiTAC are outside scope unless otherwise stated.
Official reporting mechanism
MiTAC Product Security is the single point of contact for vulnerability reporting. Reporters may choose e-mail at SWsecurity@mitacmdt.com, or the online reporting form at [https://www.mitacmdt.com/en/contacts/general-inquiry/]. The online form is optional and is not the only available reporting method.
Accessibility
If you cannot use the reporting channels above because of an accessibility need, contact Biuro@mic.com for assistance or an alternative reporting method.
Minimum report contents
- Affected product, model, software or firmware version, and configuration.
- Description of the issue, expected and observed behavior, and potential impact.
- Reproduction steps and relevant evidence, such as logs, screenshots, or a video.
- Any known exploitation, incident, CVE/CWE information, or suggested mitigation.
- Your contact details and preferred public attribution, if any.
Please do not send unnecessary personal data, credentials, customer data, or trade secrets.
Data Protection & GDPR Compliance
Personal data provided in your report, such as your name, email address, or contact details, will be processed in accordance with applicable data protection laws, including, where applicable, the General Data Protection Regulation (GDPR).
- Purpose: We use your personal data solely to process your report, communicate with you regarding the reported vulnerability, and acknowledge your contribution, if requested.
- Lawful Basis: Where GDPR applies, processing is based on our legitimate interest in maintaining system security and handling security reports, or where applicable, on your consent.
- Retention & Security: Your personal data will be retained only as long as necessary to fulfill these purposes and will be kept confidential and protected by appropriate security measures. Your personal data will not be shared with third parties unless to fulfill these purposes, with your consent, or as required or permitted by applicable law.
- Your Rights: Where applicable under the GDPR, you have the right to access, rectify, or request the deletion of your personal data, as well as other rights provided by the appliable data protection laws. You may exercise your right by contacting us at SWsecurity@mitacmdt.com.
Communication expectations
MiTAC generally aims to acknowledge external reports within three (3) working days of receipt through an official channel, where a usable contact method is provided. For reports under active handling, MiTAC generally provides a status update at least every fifteen (15) working days and following material changes, unless communication is prohibited by law or authority, would increase cybersecurity risk, or no usable contact information is available.
Confidentiality/sharing
MiTAC protects non-public vulnerability information and limits access to those with a need to know. MiTAC may share necessary information with affected suppliers, customers, coordinators, CSIRTs, service providers, or authorities for assessment, remediation, coordination, or compliance. Reporters are asked to coordinate public disclosure with MiTAC and avoid publishing exploit-enabling details before remediation or agreed disclosure. Such sharing will not include the reporter’s identity or other personal data unless the reporter has provided explicit consent or such disclosure is required or permitted by applicable law.
Remediation/disclosure timeframe
MiTAC will address and remediate confirmed vulnerabilities without undue delay based on risk. Where risk permits, MiTAC generally targets remediation and coordinated disclosure within 90 calendar days follow invalidation of a sufficiently complete report; urgent mitigations or warnings may be issued earlier where appropriate. During the applicable support period, security updates will be disseminated without delay and, unless otherwise agreed for a tailor-made product provided to a business user, free of charge, together with clear advisory information. After becoming aware of an actively exploited vulnerability or a severe incident, MiTAC will, as appropriate, inform impacted users and, where permitted by the circumstances, other affected users, and provide available risk-mitigation or corrective measures. Any embargo will be mutually agreed and documented on a case-by-case basis, including its scope and planned disclosure date. The embargo period may be shortened or extended based on factors including risk, active exploitation, remediation availability, and coordination needs. Any change to the planned disclosure date will be communicated without undue delay. No embargo will be indefinite.
Full technical publication may be delayed beyond the target date only in duly justified cases where a documented assessment determines that the risks of publication outweigh the benefits. in such cases, affected users will nevertheless receive sufficient information to identify the affected product, obtain or apply the applicable update, and take appropriate protective measures. A planned date for full disclosure will be also communicated.
Advisory/remediation publication
MiTAC will publish vulnerability advisories at [https://www.mitacmdt.com/en/contacts/cra-cvd-policy], as appropriate. Advisories will identify affected products, impact, severity, available security updates or other remediation, workarounds or mitigations, and required user actions, where applicable. After a security update or other corrective measure become available, MiTAC will publish a vulnerability advisory without undue delay at [https://www.mitacmdt.com/en/contacts/cra-cvd-policy], including information on affected products, impact, severity, remediation, and required user actions.
Good-faith research
- Test only what is necessary to demonstrate the issue and avoid harm, disruption, privacy violations, or unnecessary access to data.
- Do not use social engineering, physical attacks, denial-of-service testing, destructive actions, or unauthorized access to third-party assets.
- Stop testing and notify MiTAC promptly if unintended access, data exposure, or service impact occurs.
- Comply with applicable laws and protect all non-public information obtained during research.
Policy maintenance
MiTAC may update this policy and its reporting arrangements from time to time. The latest version of this policy is published at [https://www.mitacmdt.com/en/contacts/cra-cvd-policy]. The policy is reviewed at least annually and as appropriate following material changes. The effective date and last updated date are indicated above.
Secure communication
For sensitive vulnerability information, use the HTTPS reporting form at [https://www.mitacmdt.com/en/contacts/general-inquiry/], or encrypted e-mail using the verification.
Anonymous reporting
Anonymous or pseudonymous reports are accepted where permitted by law. MiTAC may be unable to provide status updates or recognize the reporter where no usable contact information is provided.
Reporter recognition
When appropriate, MiTAC may publish advisories or other relevant information, including security updates, mitigations, workarounds, affected-products, and vulnerability identifiers. MiTAC may recognize a reporter only with the reporter’s consent and subject to applicable confidentiality, privacy, legal, contractual, and security considerations.
No blanket NDA
MiTAC does not require reporters to enter into a blanket or indefinite non-disclosure agreement as a condition of reporting. Case-specific confidentiality arrangements may be agreed upon where necessary.
Additional legal notices
Nothing in this policy authorizes unlawful activity, testing of systems not owned or controlled by MiTAC, or conduct that violates applicable sanctions, export control requirements, contractual restrictions, or third-party rights.