⚠ 本頁尚未完成客製(CONFIG 內仍有【】待填欄位),請勿正式發布。 This page has unfilled template fields and must not be published yet.

資安弱點通報

1 目的與承諾

(下稱「本公司」)重視產品安全,歡迎資安研究者及任何第三人(下稱「通報者」)善意通報本公司產品之資安弱點。本公司承諾依本政策及時處理通報、與通報者協調揭露,並對符合本政策之善意研究提供第 6 條之安全港保障。

2 適用範圍

本政策適用於下列本公司產品及其軟體、韌體:

下列行為不在本政策適用(授權)範圍:

  • 對本公司或第三人系統之阻斷服務(DoS/DDoS)測試或壓力測試
  • 對本公司人員之社交工程、釣魚或冒用行為
  • 實體入侵、竊取或破壞行為
  • 對非本公司營運之第三方服務、雲端平台或上游供應商系統之測試
  • 大量自動化掃描致服務品質劣化之行為

3 通報方式

通報信箱:

請盡量提供:受影響產品與版本、弱點類型與重現步驟(PoC)、影響評估、您希望的揭露方式與具名/匿名意願。接受匿名通報。通報以中文或英文為之皆可。

4 我們的處理承諾

階段時限內容
收受確認收到後即時(系統自動)回覆案件編號與本政策連結
初步回覆 個營業日內人員確認通報內容、必要時請求補充
狀態更新至少每 日一次告知處理進度,直至結案
修補目標依嚴重度個案評估完成修補、發布更新與(如適用)安全公告

5 協同揭露

  • 本公司採協同弱點揭露原則:預設自通報之日起 內完成修補並協調公開;複雜案件得與通報者協商延長,涉及使用者重大風險者得協商提前。
  • 在協調之公開日前,請通報者勿向第三人揭露弱點細節。
  • 經通報者同意,本公司將於安全公告中具名致謝;亦尊重匿名意願。
  • 本政策非漏洞獎勵(bug bounty)計畫,通報不提供金錢報酬。

6 安全港(Safe Harbor)條款

善意研究之要件

通報者之研究及通報行為同時符合下列各款者,為本政策所稱之「善意研究」:

  1. 以發現並通報弱點為唯一目的,未逾越驗證弱點存在所必要之最小範圍
  2. 未破壞、竄改或刪除任何資料;未影響任何系統之可用性;未安裝持續性存取機制
  3. 因驗證而不可避免接觸他人資料者,接觸範圍以最小必要為限,未複製、保留、散布該資料,並於通報後刪除
  4. 未以弱點資訊為勒索、恐嚇、出售或其他不法目的之利用
  5. 於協調公開日前,未向第三人揭露弱點細節
  6. 遵守本政策第 2 條之範圍限制

本公司之承諾

對於符合前項之善意研究:

  1. 本公司視其為經本公司授權之安全測試行為,不主張其違反本公司服務條款或使用授權。
  2. 在法律許可範圍內,本公司承諾不對該善意研究行為提起民事訴訟、不提出刑事告訴或告發,亦不請求損害賠償。
  3. 第三人(含本公司之上游供應商或其他受影響廠商)之權利非本公司所能處分,本公司無法代其承諾;涉及第三人系統或權利之行為不在本安全港範圍。
  4. 通報者對其行為是否符合本政策有疑義時,請先來信詢問,本公司將於 個營業日內回覆。

7 個人資料與保密

  • 通報者提供之個人資料,僅用於通報處理、聯繫與致謝,依個人資料保護法辦理;匿名通報不在此限。
  • 本公司對通報內容於修補完成並協調公開前予以保密。

8 政策變更與聯絡

本政策由本公司發布並得隨時修訂,修訂後於本頁公告。政策詢問:

1  Purpose and Commitment

(the "Company", "we") values product security and welcomes good-faith reports of security vulnerabilities in our products from security researchers and any third party ("reporters"). We commit to handling reports in a timely manner under this policy, coordinating disclosure with reporters, and providing the safe harbor protections in Section 6 for good-faith research that complies with this policy.

2  Scope

This policy applies to the following Company products, including their software and firmware:

The following activities are not within the scope (authorization) of this policy:

  • Denial-of-service (DoS/DDoS) or stress testing against systems of the Company or any third party
  • Social engineering, phishing, or impersonation targeting Company personnel
  • Physical intrusion, theft, or destruction
  • Testing of third-party services, cloud platforms, or upstream supplier systems not operated by the Company
  • Large-scale automated scanning that degrades service quality

3  How to Report

Reporting mailbox:

Where possible, please include: affected product and version, vulnerability type and steps to reproduce (PoC), impact assessment, your preferred disclosure approach, and whether you wish to be credited or remain anonymous. Anonymous reports are accepted. Reports may be submitted in Chinese or English.

4  Our Handling Commitments

StageTimelineDescription
AcknowledgementImmediately upon receipt (automated)Case number and a link to this policy
Initial responseWithin business daysStaff review the report and request further details if needed
Status updatesAt least every daysProgress updates until the case is closed
Remediation targetCase-by-case, based on severityRemediation, update release, and (where applicable) a security advisory

5  Coordinated Disclosure

  • We follow the principle of coordinated vulnerability disclosure: by default, we aim to complete remediation and coordinate public disclosure within days from the date of report. Complex cases may be extended by mutual agreement; disclosure may be brought forward by agreement where users face significant risk.
  • Please do not disclose vulnerability details to any third party before the coordinated disclosure date.
  • With the reporter's consent, we will credit the reporter in our security advisory; requests for anonymity are equally respected.
  • This policy is not a bug bounty program; no monetary reward is provided for reports.

6  Safe Harbor

Criteria for good-faith research

Research and reporting activities that satisfy all of the following constitute "good-faith research" under this policy:

  1. Conducted solely to discover and report vulnerabilities, without exceeding the minimum scope necessary to verify that a vulnerability exists
  2. No destruction, alteration, or deletion of any data; no impact on the availability of any system; no installation of persistent-access mechanisms
  3. Where contact with others' data is unavoidable for verification, such contact is limited to the minimum necessary; the data is not copied, retained, or distributed, and is deleted after reporting
  4. No use of vulnerability information for extortion, threats, sale, or any other unlawful purpose
  5. No disclosure of vulnerability details to any third party before the coordinated disclosure date
  6. Compliance with the scope restrictions in Section 2 of this policy

The Company's commitments

For good-faith research that satisfies the above:

  1. We regard it as security testing authorized by the Company and will not assert that it violates our terms of service or license terms.
  2. To the extent permitted by law, we commit not to initiate civil proceedings, file criminal complaints or referrals, or claim damages in respect of such good-faith research.
  3. The rights of third parties (including our upstream suppliers and other affected vendors) are not ours to waive; activities involving third-party systems or rights fall outside this safe harbor.
  4. If you are unsure whether your activities comply with this policy, please contact us first; we will respond within business days.

7  Personal Data and Confidentiality

  • Personal data provided by reporters is used solely for report handling, communication, and acknowledgement, in accordance with the Personal Data Protection Act of Taiwan; anonymous reports are excepted.
  • We keep the contents of reports confidential until remediation is complete and public disclosure has been coordinated.

8  Policy Changes and Contact

This policy is published by the Company and may be revised at any time; revisions will be announced on this page. Questions about this policy: .

This English version is a translation provided for reference. In case of any discrepancy, the Chinese version shall prevail.