Vulnerability Disclosure Policy
Purpose
The purpose of this Vulnerability Disclosure Program (VDP) is to provide a clear and secure mechanism for external researchers, customers, and partners to report security vulnerabilities in our products and services. It supports compliance with the EU Cyber Resilience Act (CRA), specifically Article 13, Annex I and II regarding vulnerability handling and coordinated disclosure.
Scope
This program covers:
- All Products with Digital Elements (PDEs) developed, maintained, or distributed by ATS
- Hosted services and cloud-based infrastructure under ATS control
Responsible Disclosure Policy
We ask security researchers, customers, and partners to:
- Act in good faith and avoid violating privacy, disrupting services, or accessing data without authorization
- Promptly report discovered vulnerabilities via our official channel (see Reporting a vulnerability)
- Allow us a reasonable amount of time to resolve the issue before publicly disclosing any details
We commit to:
- Responding within 5 business days
- Providing regular updates during triage and remediation
- Not pursuing legal action against researchers acting in good faith
In-Scope Vulnerabilities
We are interested in vulnerabilities including (but not limited to):
- Remote Code Execution (RCE)
- Authentication or Authorization bypass
- Cross-Site Scripting (XSS)
- SQL/Command Injection
- Insecure default configurations
- Privilege escalation
- Exposed sensitive data or credentials
- Insecure deserialization or memory corruption
Out-of-Scope Submissions
These issues are generally not eligible under the VDP unless they pose high risk:
- Denial-of-Service attacks (DoS/DDoS)
- Use of outdated libraries without proven exploitability
- Clickjacking on non-sensitive pages
- Social engineering/phishing
- Lack of DNSSEC, SPF/DMARC issues without direct exploitation
Reporting a vulnerability
To report a vulnerability for coordination, click the button below to navigate to the submission form on the ATS website. If you believe a vulnerability is being actively exploited, please flag it as URGENT in the subject line.
Report a vulnerabilityPlease include:
- A clear description of the vulnerability
- Product name, version, and environment (if applicable)
- Steps to reproduce (PoC, scripts, screenshots)
- Your contact information (optional)
Handling Process
| Step | Description | Timeline |
|---|---|---|
| 1. Acknowledgment | Confirm receipt of report | Within 5 business days |
| 2. Triage | Assess validity, impact, and scope | Within 10 business days |
| 3. Remediation | Fix vulnerability and test patch | Varies by severity |
| 4. Coordination | Work with reporter on disclosure | Throughout process |
| 5. Disclosure | Public disclosure after fix is deployed | Varies by severity |
Legal Safe Harbor
This program provides legal safe harbor under the following conditions:
- Your research is conducted in good faith and within the scope defined here
- You avoid violating user privacy or disrupting systems
- You do not exploit or retain access after discovering the vulnerability
Contact information
If you have questions about this policy or need clarification: