HTML5 Test



Vulnerability Disclosure Policy

Purpose

The purpose of this Vulnerability Disclosure Program (VDP) is to provide a clear and secure mechanism for external researchers, customers, and partners to report security vulnerabilities in our products and services. It supports compliance with the EU Cyber Resilience Act (CRA), specifically Article 13, Annex I and II regarding vulnerability handling and coordinated disclosure.

Scope

This program covers:

  • All Products with Digital Elements (PDEs) developed, maintained, or distributed by ATS
  • Hosted services and cloud-based infrastructure under ATS control

Responsible Disclosure Policy

We ask security researchers, customers, and partners to:

  • Act in good faith and avoid violating privacy, disrupting services, or accessing data without authorization
  • Promptly report discovered vulnerabilities via our official channel (see Reporting a vulnerability)
  • Allow us a reasonable amount of time to resolve the issue before publicly disclosing any details

We commit to:

  • Responding within 5 business days
  • Providing regular updates during triage and remediation
  • Not pursuing legal action against researchers acting in good faith

In-Scope Vulnerabilities

We are interested in vulnerabilities including (but not limited to):

  • Remote Code Execution (RCE)
  • Authentication or Authorization bypass
  • Cross-Site Scripting (XSS)
  • SQL/Command Injection
  • Insecure default configurations
  • Privilege escalation
  • Exposed sensitive data or credentials
  • Insecure deserialization or memory corruption

Out-of-Scope Submissions

These issues are generally not eligible under the VDP unless they pose high risk:

  • Denial-of-Service attacks (DoS/DDoS)
  • Use of outdated libraries without proven exploitability
  • Clickjacking on non-sensitive pages
  • Social engineering/phishing
  • Lack of DNSSEC, SPF/DMARC issues without direct exploitation

Reporting a vulnerability

To report a vulnerability for coordination, click the button below to navigate to the submission form on the ATS website. If you believe a vulnerability is being actively exploited, please flag it as URGENT in the subject line.

Report a vulnerability

Please include:

  • A clear description of the vulnerability
  • Product name, version, and environment (if applicable)
  • Steps to reproduce (PoC, scripts, screenshots)
  • Your contact information (optional)

Handling Process

Step Description Timeline
1. Acknowledgment Confirm receipt of report Within 5 business days
2. Triage Assess validity, impact, and scope Within 10 business days
3. Remediation Fix vulnerability and test patch Varies by severity
4. Coordination Work with reporter on disclosure Throughout process
5. Disclosure Public disclosure after fix is deployed Varies by severity

Legal Safe Harbor

This program provides legal safe harbor under the following conditions:

  • Your research is conducted in good faith and within the scope defined here
  • You avoid violating user privacy or disrupting systems
  • You do not exploit or retain access after discovering the vulnerability

Contact information

If you have questions about this policy or need clarification: