![]() |
| EETI PSIRT - Coordinated Vulnerability Disclosure Policy |
![]() |
| 1. Purpose At eGalax_eMPIA Technology Inc., product security is a fundamental commitment to our customers and partners. We recognize the valuable contributions of external security researchers and users in strengthening product security. This policy provides a structured framework for reporting identified security issues. This policy applies to potential security vulnerabilities in EETI hardware products, firmware, and software utilities. It outlines the procedure for submitting potential vulnerabilities to us, and the communication process with customers and relevant parties upon confirmation of a vulnerability. EETI’s vulnerability handling and disclosure processes are designed to align with the EU Cyber Resilience Act (Regulation (EU) 2024/2847), including the reporting obligations applicable from 11 September 2026. 2. Vulnerability Submission Process To report a potential security vulnerability in one of our products, please contact our Product Security Incident Response Team (PSIRT) via email at PSIRT@eeti.com. Please include [SECURITY] in the subject line to help us prioritize your report. This mailbox is exclusively for security vulnerability reports; business inquiries, partnership proposals, and general technical support requests should be directed through other appropriate channels. All communications and reports must be submitted in English. Given the sensitive nature of these reports, EETI recommends encrypting all potential security vulnerability submissions using the PSIRT PGP/GPG Key : Fingerprint : 861F27FDBBBCEAF2E7429A4AA561FF12606D9906 Public Key File : PublicKey.zip Free software for creating and reading PGP/GPG encrypted messages is available from GnuPG To facilitate an effective assessment, reporters are requested to include the following information : • Product name, model, and version • A complete description of the issue, including detailed steps to reproduce it • An evaluation of the potential impact or risk, along with any supporting materials such as screenshots or proof-of-concept code. • Your contact information Personal data provided by reporters will be processed in accordance with the EETI Privacy Policy, solely for the purposes of vulnerability handling and coordination. Please ensure that submissions do not contain any third-party personal data. While we handle all incoming correspondence in accordance with applicable privacy regulations, any unsolicited personal data that was not explicitly requested may be deleted without further notice. Upon receipt, we aim to complete a preliminary assessment within 5 business days and to provide a written response within 10 business days. We target providing a fix or mitigation within 90 days of the initial report; complex cases, such as those requiring multi-party coordination, may take longer, in which case we will keep the reporter informed. 3.Security Advisories Once a vulnerability has been remediated and coordination with relevant OEM customers is complete, a security advisory will be published on the respective product page of our official website at www.eeti.com. Advisories will be issued only after a patch or workaround is available and all known OEM customers have been duly informed. Where a CVE (or equivalent EUVD) identifier is assigned, it will be referenced in the advisory. In cases where a vulnerability is reported by an external researcher, an internal review will be conducted, and a coordinated disclosure may follow in collaboration with the reporting party. If a report is submitted under a confidentiality agreement, efforts toward a resolution will proceed, and the scope of publicly available details regarding the vulnerability may be restricted. In cases involving multiple OEMs or requiring cross-organizational coordination, the resolution timeline may be reasonably extended as necessary. Where necessary for coordinated handling or where required by law, including under the EU Cyber Resilience Act, relevant information from a report may be shared with affected parties, coordination bodies, or competent authorities. 4.Severity Assessment We employ the latest edition of the Common Vulnerability Scoring System (CVSS) as our benchmark for severity evaluation, aligning with established industry practice. Security advisories will detail the scope of affected products and outline the necessary remediation steps. Given that OEM partners might distribute products in various version configurations, the list of affected versions may not always be comprehensive. For inquiries about a specific version, please contact us at PSIRT@eeti.com. 5.Acknowledgement We sincerely acknowledge the contributions of individuals who enhance the security of our products. Researchers who submit valid vulnerability reports will, with their consent, be publicly acknowledged in the corresponding security advisory, or may choose to remain anonymous, in recognition of their contribution to product security. 6.Safe Harbor EETI will not pursue legal action against security researchers who act in good faith and in accordance with this policy. To remain within this safe harbor, research must stay within the scope of this policy and must not involve privacy violations, destruction or exfiltration of data beyond what is necessary to demonstrate the vulnerability, disruption of our services, or any form of extortion. Researchers are expected to give EETI a reasonable opportunity to remediate the reported vulnerability before any public disclosure, consistent with the coordinated disclosure timeline set out in this policy. This safe harbor reflects EETI’s own position only; it does not bind third parties or law-enforcement authorities, and it does not authorize testing of systems, networks, or products owned or operated by third parties, including third-party products that incorporate EETI components. Research conducted in good faith and in accordance with this policy is considered authorized by EETI. If you are unsure whether a specific action is authorized, please contact us at PSIRT@eeti.com before proceeding. |
| Copyright © EETI 2000.2026 eGalax_eMPIA Technology Inc. Privacy Policy |
© Website picture is for reference only. Please feel free to contact us for more information. touch_sales@eeti.com touch_fae@eeti.com |
11F., No.302, Rueiguang Rd., Neihu District, Taipei City 114, Taiwan T: +886 2 8751 5191 F: +886 2 2797 8808 |