Coordinated Vulnerability Disclosure Policy

AuthenTrend Technology Inc.

Version 1.3 · Last updated: 20 August 2026

Our commitment

AuthenTrend takes the security of its products seriously. We welcome reports from security researchers, customers, and the public about potential vulnerabilities in our products (the ATKey series of hardware security keys and related software). This policy explains how to report a vulnerability to us and what you can expect in return.

How to report a vulnerability

Please send reports to security@authentrend.com.

To help us assess and resolve the issue quickly, include where possible:

  • The affected product, model, and firmware/software version

  • A description of the vulnerability and its potential impact

  • Steps to reproduce, proof-of-concept, or configuration details

  • Your contact information so we can follow up

Reports are accepted in English or Traditional Chinese.

If your report contains details you would prefer not to send by ordinary email, say so in your first message and we will agree a secure channel with you before you share them.

What you can expect from us

  • Acknowledgement — we aim to confirm receipt of your report within 3 business days.

  • An initial assessment and, where relevant, a request for further information.

  • Regular updates on our progress toward a resolution.

  • Credit for your discovery once the issue is resolved, if you wish to be named.

Regulatory reporting

Where a reported vulnerability is found to be actively exploited, or where it relates to a severe security incident, AuthenTrend has reporting obligations to the relevant EU authorities under Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). In those cases we will notify the designated CSIRT and ENISA within the statutory deadlines and will inform affected users.

We will tell you if your report triggers this process. Regulatory notifications do not identify you as the reporter unless you have asked to be credited and we have agreed that with you first.

Our commitment to you (safe harbour)

We will not pursue or support legal action against researchers who:

  • Act in good faith and in accordance with this policy;

  • Avoid privacy violations, service disruption, and destruction or exfiltration of data;

  • Give us reasonable time to investigate and remediate before any public disclosure;

  • Do not exploit the vulnerability beyond the minimum necessary to demonstrate it.

Scope

In scope

  • ATKey hardware security keys (all models) that you own — including physical, invasive, and side-channel testing

  • AuthenTrend firmware, software, and mobile or desktop applications

  • AuthenTrend web services, tested against your own account and your own data only

Out of scope

  • Systems, devices, accounts, or data belonging to other parties

  • Denial-of-service, load, or stress testing against our services

  • Third-party products and services that AuthenTrend does not operate, including customer deployments and identity providers that integrate with our products

If you are unsure whether something is in scope, contact us before you begin and we will tell you.

Coordinated disclosure

We ask that you keep the details of any vulnerability confidential until we have released a fix or agreed a disclosure timeline with you. We aim to remediate valid vulnerabilities promptly and will coordinate public disclosure with you where appropriate.

Contact: security@authentrend.com

AuthenTrend Technology Inc. — 12F.-2, No. 66, Sanchong Rd., Nangang Dist., Taipei City 115, Taiwan