
Vulnerability Disclosure Policy
Purpose
CTC Union is committed to delivering secure and reliable products, and integrates cybersecurity into every stage of product design and development. We have established a comprehensive vulnerability reporting and handling mechanism that provides external security researchers, partners, and users with a secure and transparent disclosure channel. This helps us identify, assess, and remediate potential vulnerabilities at an early stage, reduce cybersecurity risk, and continuously improve the security and reliability of our products.
To ensure that product security vulnerabilities are handled promptly and appropriately, CTC Union has established a Product Security Incident Response Team (PSIRT), dedicated to receiving, analyzing, validating, and coordinating the handling of product security incidents and vulnerability reports. We follow international standards and industry best practices, continuously refining our vulnerability management and incident response processes, and work together with security researchers, partners, and customers to maintain product security, reduce potential cybersecurity risk, and deliver safer, more reliable products and services.
If you discover a security vulnerability that may affect the security of a CTC Union product or service, please report it to the Product Security Incident Response Team (PSIRT) via the Vulnerability Reporting System. For further contact, please call CTC Union at +886-2-2659-1021.
CTC Union's Product Security Incident Response Team (PSIRT) handles product security vulnerabilities in accordance with a standardized vulnerability management process, as follows:

1. Intake and Acknowledgment
After PSIRT receives a vulnerability report, the reporter will typically receive a response within 2 business days acknowledging that the report has been received and that a follow-up assessment is underway.
2. Vulnerability Classification and Risk Assessment
PSIRT performs an initial classification, technical analysis, and risk assessment of the vulnerability to confirm whether it exists and to determine its potential impact on the product, system, and customers.
3. Root Cause Analysis and Remediation Planning
PSIRT works with relevant departments, including Product Management (PM), R&D, and Design Quality Assurance (DQA), to analyze the root cause of the vulnerability, determine the scope of impact, and develop a remediation or mitigation plan. Where the reporter has provided contact information, PSIRT will provide progress updates as appropriate throughout the process.
4. Remediation
PSIRT works with the product development team to complete the development, testing, and verification of the remediation. High-risk or critical vulnerabilities are prioritized for resources. If development of an official patch requires additional time, temporary mitigation measures will be provided where appropriate to reduce potential risk in the interim.
5. Security Advisory and Disclosure
Once a vulnerability has been analyzed and remediated, PSIRT will, as needed, issue a Security Advisory describing the vulnerability, the affected products and versions, the risk level, mitigation measures, patch information, and related recommendations, and will publish it in the Security Advisories section.
PSIRT uses the industry-standard Common Vulnerability Scoring System (CVSS) as the basis for vulnerability risk assessment, taking into account exploitability, impact, and the actual product environment, to determine the severity rating. This rating is used to set handling priority, remediation timelines, and the approach to information disclosure.
| Severity Level | CVSS 3.x Score Range |
|---|---|
| Critical | 9.0 – 10.0 |
| High | 7.0 – 8.9 |
| Medium | 4.0 – 6.9 |
| Low | 0 – 3.9 |
For lawful security research conducted in good faith and in accordance with this policy, CTC Union will handle the resulting vulnerability reports with respect and a cooperative approach.
Continuous Monitoring and Improvement
CTC Union continuously reviews and optimizes its product cybersecurity management processes. Through vulnerability analysis, incident review, and risk assessment, lessons learned are fed back into product design, development, and maintenance processes to continuously improve product security and resilience.
We also continue to reference international cybersecurity standards, relevant government guidance, and industry best practices, and maintain ongoing collaboration with security researchers and partners to jointly reduce product cybersecurity risk and deliver safer, more reliable products and services.
CTC Union reserves the right to revise this policy at any time without prior notice; the most current version will be published on the official website.
This policy serves solely as a guideline for reporting and coordinating the handling of product security vulnerabilities. It does not constitute any legal right, obligation, or guarantee. CTC Union retains final decision-making authority over the acceptance, handling, remediation, and disclosure of vulnerability reports.
To report a product security vulnerability, or if you have any questions about this policy, please contact the Product Security Incident Response Team (PSIRT) at PSIRT@ctcu.com.