Coordinated Vulnerability Disclosure Policy

Portwell is committed to building secure products and responding responsibly to product cybersecurity vulnerability reports throughout the support lifecycle.

Our Commitment

Portwell values vulnerability reports from independent security researchers, customers, partners, and other stakeholders. We follow Coordinated Vulnerability Disclosure (CVD) principles and handle reported or suspected vulnerabilities responsibly and transparently, with customer risk reduction as our priority. We aim to work constructively with reporters, assess the affected scope, plan remediation or mitigation, and coordinate public disclosure at the appropriate time.

Cybersecurity Governance and Regulatory Resilience

Portwell obtained IEC 62443-4-1 certification in 2026 and continues to integrate secure development lifecycle practices, product vulnerability management, and supply-chain coordination into product cybersecurity governance. Where applicable, our disclosure and reporting activities are aligned with requirements under the EU Cyber Resilience Act (CRA), including appropriate assessment and coordination for actively exploited vulnerabilities, severe cybersecurity incidents, and related corrective measures. This policy is not limited to the CRA: Portwell also seeks to meet or support other applicable product cybersecurity, cyber-resilience, privacy, notification, and customer-contract requirements.

Scope

This policy applies to standard Portwell products, supported firmware and software, Portwell-operated services, and official websites within their support lifecycle. Portwell will address custom products, end-of-life products, and third-party components to the extent it can reasonably control remediation or coordination; obligations for custom products remain subject to the applicable agreement. This policy does not replace product documentation, warranty terms, service agreements, or legal obligations.

Vulnerability Reporting

Reporting Policy and Principles

Portwell is committed to maintaining a rigorous, traceable, and continuously improving product cybersecurity vulnerability management program. We provide customers with reliable product security information, risk assessments, and practical mitigation guidance to reduce the potential impact of product vulnerabilities. The Product Security Incident Response Team (PSIRT) is Portwell’s dedicated function for receiving and managing product security incidents and vulnerability reports, including intake, technical validation, risk assessment, remediation coordination, and related disclosure activities.

Portwell continuously considers international standards, regulatory requirements, and recognized industry practices to strengthen its vulnerability-handling process and response capability. Through timely, responsible, and transparent coordination with researchers, customers, suppliers, and other stakeholders, we seek to improve the cyber resilience of industrial and embedded products and remain a trusted product-security partner.

Reporting Channel and Submission Guidance

Please submit potential product or service vulnerabilities to the Portwell PSIRT. To support efficient validation, investigation, and response, reports should include the following information where available. This list is a guide and does not limit the submission of other information that may assist our assessment.

  • Reporter contact details, including name, organization, and email.
  • The affected Portwell product name, model, hardware revision, and firmware or software version.
  • A technical description of the vulnerability, expected and actual behavior, and known or potential impact.
  • Reproduction steps, including required equipment, software, configuration, network environment, and sequence of actions where applicable.
  • Proof-of-concept (PoC) material, screenshots, logs, packet captures, non-malicious test code, or other supporting evidence.
  • How an attacker could exploit the issue, including prerequisites and the potential attack path.
  • Any other information that may help clarify the vulnerability’s scope, impact, or remediation options.

To make submission as easy as possible, we offer two reporting methods:

Option 1: Secure Email ( For Sensitive Attachments )

If your report includes highly sensitive supporting evidence (such as detailed logs or PoC test code), we strongly recommend using PGP encryption via email.

 

※ Please use the Portwell public key to encrypt sensitive report content.

Option 2 : Online Submission Form

You can submit your findings directly using our secure online form, which includes all the necessary fields to help us assess your report efficiently.

Personal Data Protection:

For the secure submission of sensitive information, you may use the public key provided by Portwell to encrypt your email content. Please provide only personal data necessary to process the report and avoid sending unnecessary customer data, credentials, or other information you are not authorized to share.

Safe Harbor:

Portwell will not initiate legal action against security researchers solely because they conduct vulnerability research in good faith, comply with this policy, and seek to identify or reduce cybersecurity risk.

Product Cybersecurity Vulnerability Management Process

Portwell continuously strengthens its capability to identify, assess, remediate, and disclose product cybersecurity vulnerabilities by considering international standards, applicable regulations, and recognized industry practices. This process is founded on Coordinated Vulnerability Disclosure principles and balances communication with reporters, customer protection, product security, and regulatory compliance. Timelines are adjusted according to risk, reproducibility, affected scope, exploitability, and case complexity. Unless a statutory obligation expressly applies, the timelines below are operational targets and not guarantees for individual cases.

Stage 1: Initial Response

After receiving an external vulnerability report concerning a Portwell product, the PSIRT records the submission, performs an initial acknowledgement, and establishes a communication channel. Our target is to respond within two business days, confirm that the report has been received, and explain the next steps where practical. The PSIRT may request additional information when needed for validation and investigation.

Stage 2: Assessment and Classification

The PSIRT promptly evaluates report reproducibility and classifies risk based on vulnerability characteristics, affected products and versions, exploitability, exposure, operational or safety impact, and available compensating controls. Each accepted vulnerability report will be assigned a unique tracking identifier and managed through Portwell’s vulnerability management process. Relevant records, assessment results, remediation activities, and disclosure decisions may be retained to support product security management, regulatory compliance, and continuous improvement. Our target is to provide the reporter with an initial assessment or status update within 24 hours after sufficient information is available. For cases subject to reporting obligations under the CRA or other applicable regulations, Portwell assesses whether notification to designated authorities, the coordinating CSIRT, ENISA, or other relevant bodies is required. For example, where the CRA applies and an actively exploited vulnerability is confirmed, an early warning notification is made as required and no later than 24 hours after awareness.

Stage 3: Investigation and Regulatory Notification

Portwell coordinates product engineering, quality, suppliers, and other necessary parties through the PSIRT to investigate root cause, affected scope, exploitation conditions, and potential impact, and to develop initial corrective or mitigating measures. Our target is to complete practical initial investigation and information gathering within 72 hours and to communicate the known nature of the issue, impact summary, and available actions to the reporter.

Where a case triggers an external notification duty under applicable law, Portwell provides the required information within the statutory deadline. For example, where the CRA applies and an actively exploited vulnerability is confirmed, the relevant notification is due no later than 72 hours after awareness and includes available general information on the vulnerability, exploitation, and corrective or mitigating measures.

 Where a reported vulnerability involves third-party software, firmware, hardware components, open-source software, or external suppliers, Portwell may coordinate remediation, risk mitigation, and disclosure activities with the relevant suppliers, maintainers, developers, or other affected stakeholders as appropriate.

Stage 4: Remediation and Validation

Relevant Portwell teams jointly develop, test, and validate software, firmware, configuration changes, or other appropriate corrective and mitigating measures. For known exploited or high-impact vulnerabilities, Portwell prioritizes immediately available risk-reduction measures and notifies the reporter and affected customers when corrective or mitigating measures are available. Where the CRA applies and a final report is required, Portwell submits the required report no later than 14 days after a corrective or mitigating measure becomes available.

Stage 5: Coordinated Disclosure

Portwell coordinates a reasonable disclosure timeline with the reporter based on completed technical analysis, customer risk, remediation availability, and applicable legal requirements. Confirmed product cybersecurity vulnerabilities may be communicated publicly through a Security Advisory on the Portwell website. An advisory may include the vulnerability description, potentially affected products and versions, risk information, available mitigations, remediation plan or security-update information, and necessary revision history. When there is known active exploitation, an immediate safety or operational risk, prior public disclosure, or a legal requirement, Portwell may publish necessary and proportionate information or mitigation guidance before a complete fix is available.

Good-Faith Research and Safe Harbor

Portwell will treat good-faith research as authorized when it follows this policy, is intended to identify and reduce cybersecurity risk, and is promptly reported. Researchers should use only accounts, devices, and data they own or are authorized to use, minimize impact, and stop immediately if personal, confidential, credential, or customer data is encountered. Please keep non-public findings confidential until coordinated disclosure. This commitment does not cover denial-of-service, destructive or availability-impacting testing, social engineering, phishing, physical intrusion, credential theft, malware, persistence, broad scanning, brute force, or any activity that violates applicable law.

Privacy, Confidentiality, and Reservations

Portwell uses report information only for intake, validation, risk assessment, remediation, supply-chain coordination, security improvement, and applicable legal compliance. We will not disclose a reporter’s identity or non-public technical details unless necessary to handle the vulnerability, comply with a legal obligation, or with appropriate consent. This policy is not a bug-bounty program and does not guarantee compensation, acknowledgement, a particular remediation method, or a completion date. Portwell may update this policy as regulations, products, or the threat landscape evolve.

Contact

To report a suspected vulnerability or ask about this policy, contact the Portwell PSIRT at psirt@portwell.com.tw