Security Advisory
AIC Product Security
AIC is committed to ensuring product security and continuously strengthening product security and information protection in accordance with applicable laws, regulations, and relevant security requirements. We welcome customers and relevant stakeholders to report product-related security issues. AIC takes reported security vulnerabilities and security-related issues seriously and will contact the reporter when necessary to obtain additional information and assist with the investigation and handling of the reported issue.
Security Commitment
AIC regards product security as an ongoing commitment rather than a one-time effort. We continuously review and strengthen our product security processes and maintain appropriate collaboration with industry partners, security researchers, and cybersecurity professionals to continuously improve our product security and vulnerability handling capabilities.
Security Advisories
No data
Vulnerability Disclosure Policy
Responsible Reporting Guidelines
AIC welcomes customers, partners, and security researchers to report product security issues. When researching or reporting a potential vulnerability, please:
- Do not access or modify any AIC product, system, service, or software without authorization.
- Do not disclose, modify, destroy, or misuse any data obtained without authorization.
- Please keep information related to the reported security issue confidential and refrain from publicly disclosing vulnerability details until the issue has been appropriately addressed.
- Do not engage in denial-of-service (DoS) attacks or destructive testing that may affect the confidentiality, integrity, or availability of information, products, systems, or services.
- Do not conduct social engineering or phishing activities targeting AIC customers or employees.
Submission Scope
AIC welcomes reports of potential product security issues. Each submission will be reviewed based on the nature of the issue and its potential security impact.
Certain submissions may be considered lower priority or may fall outside the scope of AIC's vulnerability handling process, including issues with no demonstrated security impact, insufficient information for validation, automated scanner findings without supporting analysis, or issues unrelated to AIC products, software, firmware, or services.
AIC may evaluate submissions on a case-by-case basis based on the specific circumstances and potential security impact.
How to Report
We welcome reports concerning security vulnerabilities or product-related security issues affecting AIC products and services. If you discover a potential security vulnerability or security issue, please report it to us through our designated reporting channel.
Security Vulnerability Reporting Form:
[ https://www.aicipc.com/security/report-vulnerability/ ]
To help us address your concerns quickly, please ensure you provide the following information on the website.
- Your name and contact information — Your name and a valid email address or other contact information.
- Affected product or service — The affected AIC product, software, service, system, or component.
- Product or software version — The affected product, firmware, software, or service version, if applicable.
- Description of the security issue — A clear description of the vulnerability or security issue.
- Steps to reproduce — Clear, step-by-step instructions to reproduce the issue.
- Additional information — Any other information that may help us investigate or resolve the issue
Providing complete and accurate information will help AIC assess the reported issue more efficiently and determine appropriate remediation measures.
What Happens Next
After receiving a product security report, AIC will conduct an initial assessment accordingly. When necessary, we may contact the reporter to obtain additional information soon.
If the reported issue is confirmed, AIC will investigate and evaluate the issue and take appropriate actions in accordance with our internal vulnerability handling process. Where appropriate, we may provide the reporter with updates regarding the status of the reported issue.
Disclaimer
AIC's product security handling processes and related policies may be adjusted based on individual cases, applicable regulatory requirements, and internal processes without prior notice. The information provided on this page is intended for product security reporting and related informational purposes only. It does not constitute a guarantee of a specific outcome, response time, or remediation timeline for any particular issue. # The final disclaimer should be reviewed and approved by AIC's relevant internal legal and security personnel before publication.
