Product Security Vulnerability Disclosure Policy
Policy Statement
TSC Auto ID is committed to providing secure and reliable products and services while continuously enhancing product cybersecurity resilience. To assist customers, users, cybersecurity researchers, partners, and other stakeholders in reporting potential security vulnerabilities affecting our products, we have established a Product Security Incident Response Team (PSIRT) responsible for receiving, evaluating, verifying, remediating, and disclosing product security vulnerabilities.
We adopt a Coordinated Vulnerability Disclosure (CVD) mechanism, collaborating with vulnerability reporters and relevant stakeholders to minimize the risk of vulnerabilities being maliciously exploited and to protect the information security of all users.
Scope of Application
This policy applies to products and services developed, maintained, sold, or within their support period by TSC Auto ID, including but not limited to:
- Firmware
- Software
- APIs and communication protocols
- Cloud services
- Products integrated with third-party components and open-source components
Product versions that have reached the end of their security support are generally excluded from this policy; however, we may still evaluate actual risks to determine whether to accept a report on a case-by-case basis.

































