HOME ABOUT US
ABOUT US

XAC Responsible Disclosure

Policy

At XAC, security is our top priority. This Responsible Disclosure Policy outlines the guidelines for reporting security vulnerabilities responsibly. XAC Automation Corp (XAC) is dedicated to maintaining robust security standards for our payment solutions. We have implemented a structured vulnerability management procedure to help protect our products and customers and to support compliance with applicable regulatory and industry security requirements, including the EU Cyber Resilience Act (CRA) and PCI security requirements, where applicable.

 

We welcome reports from security researchers and partners to ensure a safe and resilient payment environment.

 

EU Cyber Resilience Act (CRA) Compliance: XAC complies with the mandatory vulnerability reporting obligations under Regulation (EU) 2024/2847. For actively exploited vulnerabilities covered by the CRA, XAC will submit an early warning notification to the relevant authorities within 24 hours of becoming aware of the vulnerability, in accordance with the applicable CRA requirements.
 

Scope

This policy applies to all XAC hardware and software products for which XAC provides security support or vulnerability management, including products subject to applicable EU CRA requirements.

 

XAC Security Maintenance Cycle

The security maintenance cycle is conducted annually to all applicable products and is also triggered immediately upon the discovery of a critical vulnerability. Phases 1 to 4 are targeted for completion as soon as reasonably practicable following detection, depending on the nature, severity, technical complexity, and overall scope of the vulnerability.

 

Phase 5 is scheduled based on the severity, impact, and technical complexity of identified vulnerabilities.

 

Phase 1: Vulnerability Detection
    • Monitoring NVD and public vulnerability databases.
    • Proactive liaison with hardware vendors for mitigation paths.
    • Receipt of private notifications from partners and customers.
 
Phase 2: Classification
    • Assessment based on CVSS 3.x/4.0 criticality (Low, Medium, High, Critical).
 
Phase 3: Mitigation Design and Planning
  • Development of technical advisories and software repair plans.
  • Security testing to validate the applicability, exploitability, and potential impact of the vulnerability.
 
Phase 4: Disclosure and Advisory
  • Dissemination of advisories to internal and external stakeholders.
  • Critical Alert: Where a critical vulnerability is validated and affected customers are identified, XAC will notify affected customers as soon as reasonably practicable and, where applicable, within 24 hours of validation.
 
Phase 5: Software Update and Release
  • Implementation and release of validated software or firmware fixes will be prioritized and scheduled based on the severity, impact, and technical complexity of the identified vulnerabilities.

 

Reporting Guidelines

If you believe you have discovered a security vulnerability affecting any XAC product within the scope of this policy, we encourage you to report it to us as soon as possible. To ensure responsible disclosure, please follow these guidelines:

 

We invite you to contact us about such matters through our dedicated web form: https://www.xac.com.tw/contact/

  • A comprehensive description of the vulnerability, including relevant details such as the URL and the type of vulnerability.
  • CVSS Score (Common Vulnerability Scoring System).
  • Sufficient information to help us reproduce the issue.
  • A screenshot of the identified vulnerability, if applicable.
  • Your contact details, including name, email, phone number, and your public PGP key (if available).
  • Technical specifics such as the endpoint, affected components (GET/POST parameters, cookies, headers, paths, HTTP methods).

 

What to Expect

Once a report is submitted, we will:

  1. Acknowledge receipt of your report within 1 business day.
  2. Investigate and validate the reported issue.
  3. Provide updates on our progress and, where reasonably practicable, an estimated remediation timeline.
  4. Notify you of the outcome of our assessment and, where applicable, when the vulnerability has been remediated.

 

Bug Bounty: XAC does not currently operate a paid bug bounty program. We do not offer monetary rewards or compensation for vulnerability reports, and submission of a vulnerability report does not create any entitlement to compensation.

 

Good-Faith Security Research Guidelines

To ensure the security of XAC and our customers, it is essential that you adhere to best practices, including:

  • Refraining from using the vulnerability to access or attempt to access information that you are not authorized to access.
  • Not exploiting the vulnerability to alter or delete any information.
  • Not performing any actions that could disrupt or degrade our services, including denial-of-service or similar attacks.
  • Not using discovered vulnerabilities for malicious purposes.
  • Not publicly disclosing the vulnerability while XAC is investigating or remediating the issue. Please coordinate any proposed public disclosure with XAC in advance.
 
Safe Harbor: XAC supports good-faith security research conducted in accordance with this policy. To the extent permitted by applicable law, XAC will generally not pursue legal action against a security researcher for activities conducted in good faith and in compliance with this policy, provided that such activities are undertaken solely for the purpose of identifying and responsibly reporting security vulnerabilities.
 

Report Anonymously

Yes. You may submit a vulnerability report anonymously. However, if you do not provide contact information, please note that XAC will not be able to acknowledge receipt, request additional information, provide status updates, or otherwise communicate with you, as we will have no means of contacting you.

 

Updates to This Policy

XAC reserves the right to update this policy at any time. Any changes will be reflected on this page. The updated version will become effective upon publication on this page.

 

Thank you for helping us maintain the security and resilience of our devices and solutions. XAC is committed to continuously improving the security of our payment solutions and maintaining robust security practices to protect our customers and partners.

 


 

© 2026 XAC Automation Corp. All rights reserved.

This policy is aligned, where applicable, with relevant industry security standards and regulatory requirements, including PCI and EU Cyber Resilience Act (Regulation EU 2024/2847).

Compare

total 0 items

In accordance with the General Data Protection Regulation (GDPR) enforced by the European Union, we are committed to protecting your personal data and giving you control over it.

By clicking "Accept All," you consent to our use of cookies to enhance your experience on this website, help us analyze site performance and usage, and deliver relevant marketing content. You can manage your cookie preferences below. By clicking "Confirm," you agree to proceed with your current settings.

Manage Cookies

Privacy Preference Center

In accordance with the General Data Protection Regulation (GDPR) enforced by the European Union, we are committed to protecting your personal data and giving you control over it.

By clicking "Accept All," you consent to our use of cookies to enhance your experience on this website, help us analyze site performance and usage, and deliver relevant marketing content. You can manage your cookie preferences below. By clicking "Confirm," you agree to proceed with your current settings.

Manage Consent Settings

Necessary Cookies

Always On

These cookies are essential for the website to function and cannot be disabled in our systems. They are usually set only in response to actions you take, such as setting your privacy preferences, logging in, or filling out forms. You can set your browser to block or alert you about these cookies, but some parts of the site may not work properly as a result.

Marketing Cookies

Marketing Cookies
Marketing cookies are used to track visitors across websites. Their purpose is to display ads that are relevant and engaging for the individual user and therefore more valuable to publishers and third-party advertisers.

Targeting Cookies
These cookies are set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant ads on other websites. They work by uniquely identifying your browser and device. If you do not allow these cookies, you will experience less targeted advertising across different sites.

Social Media Cookies
These cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building a profile of your interests. This may influence the content and messages you see on other websites. If you do not allow these cookies, you may not be able to use or view these sharing tools.