XAC Responsible Disclosure
Policy
At XAC, security is our top priority. This Responsible Disclosure Policy outlines the guidelines for reporting security vulnerabilities responsibly. XAC Automation Corp (XAC) is dedicated to maintaining robust security standards for our payment solutions. We have implemented a structured vulnerability management procedure to help protect our products and customers and to support compliance with applicable regulatory and industry security requirements, including the EU Cyber Resilience Act (CRA) and PCI security requirements, where applicable.
We welcome reports from security researchers and partners to ensure a safe and resilient payment environment.
| EU Cyber Resilience Act (CRA) Compliance: XAC complies with the mandatory vulnerability reporting obligations under Regulation (EU) 2024/2847. For actively exploited vulnerabilities covered by the CRA, XAC will submit an early warning notification to the relevant authorities within 24 hours of becoming aware of the vulnerability, in accordance with the applicable CRA requirements. |
Scope
This policy applies to all XAC hardware and software products for which XAC provides security support or vulnerability management, including products subject to applicable EU CRA requirements.
XAC Security Maintenance Cycle
The security maintenance cycle is conducted annually to all applicable products and is also triggered immediately upon the discovery of a critical vulnerability. Phases 1 to 4 are targeted for completion as soon as reasonably practicable following detection, depending on the nature, severity, technical complexity, and overall scope of the vulnerability.
Phase 5 is scheduled based on the severity, impact, and technical complexity of identified vulnerabilities.
-
- Monitoring NVD and public vulnerability databases.
- Proactive liaison with hardware vendors for mitigation paths.
- Receipt of private notifications from partners and customers.
-
- Assessment based on CVSS 3.x/4.0 criticality (Low, Medium, High, Critical).
- Development of technical advisories and software repair plans.
- Security testing to validate the applicability, exploitability, and potential impact of the vulnerability.
- Dissemination of advisories to internal and external stakeholders.
- Critical Alert: Where a critical vulnerability is validated and affected customers are identified, XAC will notify affected customers as soon as reasonably practicable and, where applicable, within 24 hours of validation.
- Implementation and release of validated software or firmware fixes will be prioritized and scheduled based on the severity, impact, and technical complexity of the identified vulnerabilities.
Reporting Guidelines
If you believe you have discovered a security vulnerability affecting any XAC product within the scope of this policy, we encourage you to report it to us as soon as possible. To ensure responsible disclosure, please follow these guidelines:
We invite you to contact us about such matters through our dedicated web form: https://www.xac.com.tw/contact/
- A comprehensive description of the vulnerability, including relevant details such as the URL and the type of vulnerability.
- CVSS Score (Common Vulnerability Scoring System).
- Sufficient information to help us reproduce the issue.
- A screenshot of the identified vulnerability, if applicable.
- Your contact details, including name, email, phone number, and your public PGP key (if available).
- Technical specifics such as the endpoint, affected components (GET/POST parameters, cookies, headers, paths, HTTP methods).
What to Expect
Once a report is submitted, we will:
- Acknowledge receipt of your report within 1 business day.
- Investigate and validate the reported issue.
- Provide updates on our progress and, where reasonably practicable, an estimated remediation timeline.
- Notify you of the outcome of our assessment and, where applicable, when the vulnerability has been remediated.
Bug Bounty: XAC does not currently operate a paid bug bounty program. We do not offer monetary rewards or compensation for vulnerability reports, and submission of a vulnerability report does not create any entitlement to compensation.
Good-Faith Security Research Guidelines
To ensure the security of XAC and our customers, it is essential that you adhere to best practices, including:
- Refraining from using the vulnerability to access or attempt to access information that you are not authorized to access.
- Not exploiting the vulnerability to alter or delete any information.
- Not performing any actions that could disrupt or degrade our services, including denial-of-service or similar attacks.
- Not using discovered vulnerabilities for malicious purposes.
- Not publicly disclosing the vulnerability while XAC is investigating or remediating the issue. Please coordinate any proposed public disclosure with XAC in advance.
| Safe Harbor: XAC supports good-faith security research conducted in accordance with this policy. To the extent permitted by applicable law, XAC will generally not pursue legal action against a security researcher for activities conducted in good faith and in compliance with this policy, provided that such activities are undertaken solely for the purpose of identifying and responsibly reporting security vulnerabilities. |
Report Anonymously
Yes. You may submit a vulnerability report anonymously. However, if you do not provide contact information, please note that XAC will not be able to acknowledge receipt, request additional information, provide status updates, or otherwise communicate with you, as we will have no means of contacting you.
Updates to This Policy
XAC reserves the right to update this policy at any time. Any changes will be reflected on this page. The updated version will become effective upon publication on this page.
Thank you for helping us maintain the security and resilience of our devices and solutions. XAC is committed to continuously improving the security of our payment solutions and maintaining robust security practices to protect our customers and partners.
© 2026 XAC Automation Corp. All rights reserved.
This policy is aligned, where applicable, with relevant industry security standards and regulatory requirements, including PCI and EU Cyber Resilience Act (Regulation EU 2024/2847).