Coordinated Vulnerability Disclosure Policy
AuthenTrend Technology Inc.
Version 1.3 · Last updated: 20 August 2026
Our commitment
AuthenTrend takes the security of its products seriously. We welcome reports from security researchers, customers, and the public about potential vulnerabilities in our products (the ATKey series of hardware security keys and related software). This policy explains how to report a vulnerability to us and what you can expect in return.
How to report a vulnerability
Please send reports to security@authentrend.com.
To help us assess and resolve the issue quickly, include where possible:
The affected product, model, and firmware/software version
A description of the vulnerability and its potential impact
Steps to reproduce, proof-of-concept, or configuration details
Your contact information so we can follow up
Reports are accepted in English or Traditional Chinese.
If your report contains details you would prefer not to send by ordinary email, say so in your first message and we will agree a secure channel with you before you share them.
What you can expect from us
Acknowledgement — we aim to confirm receipt of your report within 3 business days.
An initial assessment and, where relevant, a request for further information.
Regular updates on our progress toward a resolution.
Credit for your discovery once the issue is resolved, if you wish to be named.
Regulatory reporting
Where a reported vulnerability is found to be actively exploited, or where it relates to a severe security incident, AuthenTrend has reporting obligations to the relevant EU authorities under Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). In those cases we will notify the designated CSIRT and ENISA within the statutory deadlines and will inform affected users.
We will tell you if your report triggers this process. Regulatory notifications do not identify you as the reporter unless you have asked to be credited and we have agreed that with you first.
Our commitment to you (safe harbour)
We will not pursue or support legal action against researchers who:
Act in good faith and in accordance with this policy;
Avoid privacy violations, service disruption, and destruction or exfiltration of data;
Give us reasonable time to investigate and remediate before any public disclosure;
Do not exploit the vulnerability beyond the minimum necessary to demonstrate it.
Scope
In scope
ATKey hardware security keys (all models) that you own — including physical, invasive, and side-channel testing
AuthenTrend firmware, software, and mobile or desktop applications
AuthenTrend web services, tested against your own account and your own data only
Out of scope
Systems, devices, accounts, or data belonging to other parties
Denial-of-service, load, or stress testing against our services
Third-party products and services that AuthenTrend does not operate, including customer deployments and identity providers that integrate with our products
If you are unsure whether something is in scope, contact us before you begin and we will tell you.
Coordinated disclosure
We ask that you keep the details of any vulnerability confidential until we have released a fix or agreed a disclosure timeline with you. We aim to remediate valid vulnerabilities promptly and will coordinate public disclosure with you where appropriate.
Contact: security@authentrend.com
AuthenTrend Technology Inc. — 12F.-2, No. 66, Sanchong Rd., Nangang Dist., Taipei City 115, Taiwan
