ATS Vulnerability Disclosure Program (VDP)

Help Us Keep ATS Products Secure

ATS Corporation welcomes security researchers, customers, and members of the security community who identify and responsibly report potential security vulnerabilities in ATS products or digital services. We value collaboration and are committed to investigating and addressing valid security concerns in a timely manner.

What Can Be Reported

The ATS Vulnerability Disclosure Program covers security vulnerabilities affecting:

  • ATS hardware, firmware, and software products
  • Digital services and connected applications operated by ATS
  • Product-related interfaces and companion software applications

How to Report a Vulnerability

If you believe you have discovered a security vulnerability, please submit a report using the ATS Vulnerability Disclosure Form. Report a vulnerability

To help us investigate efficiently, please provide:

  • The affected product and version
  • A description of the vulnerability
  • Steps to reproduce the issue, if available
  • Any supporting evidence or proof-of-concept information
  • A contact method for follow-up communications (optional)
  • Anonymous reports are accepted and will be reviewed in the same manner as identified submissions.

If you choose to provide your name and contact details, the data will be used solely for the purpose of reaching out to you with any questions related to the report or for clarification purposes. No secondary use of your data is allowed.

Our Commitment

When a vulnerability report is received, ATS will:

  • Acknowledge receipt of the report
  • Assess and validate the vulnerability
  • Communicate with the reporter during the investigation process
  • Develop and implement appropriate remediation or mitigation measures
  • Coordinate public disclosure where appropriate

Responsible Security Research

ATS supports responsible, good-faith security research. Researchers acting in accordance with this program and applicable laws, while avoiding service disruption, privacy violations, or unauthorized access to customer systems, will be considered to be conducting authorized security research under this policy.

Coordinated Disclosure

We ask researchers to provide ATS with a reasonable opportunity to investigate and remediate reported vulnerabilities before publicly disclosing technical details. ATS is committed to working collaboratively with reporters to coordinate disclosure timelines and ensure customers have access to remediation guidance when available.

Recognition

ATS appreciates the efforts of individuals who help improve the security of our products. With the reporter’s consent, ATS may acknowledge their contribution in a published security advisory. ATS does not currently offer monetary rewards through this program.

Regulatory Compliance

This Vulnerability Disclosure Program supports ATS’s commitment to secure product development and fulfills the coordinated vulnerability disclosure requirements of the European Union Cyber Resilience Act.