Help Us Keep ATS Products Secure
ATS Corporation welcomes security researchers, customers, and members of the security community who identify and responsibly report potential security vulnerabilities in ATS products or digital services. We value collaboration and are committed to investigating and addressing valid security concerns in a timely manner.
What Can Be Reported
The ATS Vulnerability Disclosure Program covers security vulnerabilities affecting:
How to Report a Vulnerability
If you believe you have discovered a security vulnerability, please submit a report using the ATS Vulnerability Disclosure Form. Report a vulnerability
To help us investigate efficiently, please provide:
If you choose to provide your name and contact details, the data will be used solely for the purpose of reaching out to you with any questions related to the report or for clarification purposes. No secondary use of your data is allowed.
Our Commitment
When a vulnerability report is received, ATS will:
Responsible Security Research
ATS supports responsible, good-faith security research. Researchers acting in accordance with this program and applicable laws, while avoiding service disruption, privacy violations, or unauthorized access to customer systems, will be considered to be conducting authorized security research under this policy.
Coordinated Disclosure
We ask researchers to provide ATS with a reasonable opportunity to investigate and remediate reported vulnerabilities before publicly disclosing technical details. ATS is committed to working collaboratively with reporters to coordinate disclosure timelines and ensure customers have access to remediation guidance when available.
Recognition
ATS appreciates the efforts of individuals who help improve the security of our products. With the reporter’s consent, ATS may acknowledge their contribution in a published security advisory. ATS does not currently offer monetary rewards through this program.
Regulatory Compliance
This Vulnerability Disclosure Program supports ATS’s commitment to secure product development and fulfills the coordinated vulnerability disclosure requirements of the European Union Cyber Resilience Act.