Product Security Policy & Disclaimer

1. Product Cybersecurity Commitment

At ARBOR Technology, we understand the vital importance of cybersecurity in industrial automation, medical IoT, smart transportation, and edge computing applications. We are committed to delivering highly reliable and flexible edge computing and embedded solutions, treating product security as a fundamental pillar of our product lifecycle management.

Our dedicated team of security experts continuously works to identify potential vulnerabilities and implement proactive safeguards. This ensures that ARBOR's hardware, software, and integrated solutions can withstand evolving cybersecurity threats, safeguarding our customers' assets and operational continuity.

2. Product Security Incident Response Team (ARBOR PSIRT)

ARBOR Technology has established a dedicated Product Security Incident Response Team (ARBOR PSIRT). This cross-functional and cross-regional team centrally manages the identification, internal coordination, investigation, and reporting of cybersecurity vulnerabilities associated with ARBOR products, solutions, and services.

ARBOR PSIRT serves as the single official point of contact for customers, partners, security researchers, and vendors to report potential vulnerabilities in ARBOR products. We maintain a transparent, responsible, and proactive posture to safeguard the broader edge IoT ecosystem.

[Vulnerability Reporting Channel]

Please contact [email protected] immediately if any individual or organizations that are experiencing a product security issue. To assist the investigation, please provide as much information as possible, including:

  • Organization and contact name.
  • ARBOR Technology Products and versions affected.
  • Description of the potential vulnerability.
  • Supporting technical details (such as steps to reproduce the issue, system configuration, traces, sample packet capture).
  • Information about known exploits/attack code.

3. Incident Handling Process

ARBOR Technology employs a rigorous five-stage vulnerability response process to ensure every potential issue is addressed in a timely, effective, and transparent manner:

Step Description
Step 1: First Incident Response Upon receiving a vulnerability report, the ARBOR PSIRT will verify that the submitted information is complete, acknowledge receipt of the report, and perform initial case registration by assigning a unique tracking ID. The reporter will receive a confirmation to facilitate subsequent communication and case tracking.
Step 2: Triage & Analysis The ARBOR PSIRT will conduct an initial review and classify the reported issue to determine whether it constitutes a product security vulnerability. The team will assess the potential impact, affected products, vulnerability type, and severity. When necessary, the case will be assigned to the appropriate product development team for further technical analysis and follow-up actions.
Step 3: Investigation The ARBOR PSIRT will work closely with the relevant product development team to conduct a technical investigation, verify the existence of the vulnerability, reproduce the reported issue, analyze the root cause, and identify the affected products, versions, and potential impact. The investigation results will serve as the basis for subsequent remediation activities.
Step 4: Remediation The ARBOR PSIRT, in collaboration with the relevant product development team, will develop and implement appropriate remediation measures, including software updates, firmware fixes, configuration changes, or other suitable mitigation measures. The effectiveness of the remediation will be validated to reduce or eliminate the associated cybersecurity risks.
Step 5: Disclosure & Communication Upon completion of vulnerability remediation and validation, the ARBOR PSIRT will publish a Security Advisory in accordance with the company's Coordinated Vulnerability Disclosure (CVD) policy to inform affected customers and other relevant stakeholders. The timing and scope of the disclosure will be determined based on the severity of the vulnerability, the likelihood of exploitation, and other relevant risk considerations.

4. Security Disclaimer & Terms of Use

[Disclaimer]

By submitting any information related to product security vulnerabilities, issues, or incidents, you acknowledge and agree that ARBOR Technology may collect, process, and use such information solely for the purpose of addressing and resolving the reported issue. We are committed to protecting your privacy, and all shared information will be handled in accordance with applicable laws and our internal policies.

Furthermore, you agree that ARBOR Technology may utilize the provided information for internal investigation, analysis, and continuous improvement of our products and services. While we will make every reasonable effort to safeguard your identity and sensitive information, you understand and acknowledge that absolute anonymity cannot be guaranteed when further clarification is required or as mandated by applicable laws.

ARBOR Technology shall not be held liable for any unintended disclosures arising from information voluntarily provided by end users. You are responsible for ensuring that the information shared does not infringe upon any third-party rights or violate any legal restrictions. By submitting a report, you agree to release and hold ARBOR Technology harmless from any claims, liabilities, or obligations resulting from the use or disclosure of the provided information.

While ARBOR Technology makes reasonable efforts to ensure the accuracy and timeliness of the information and security patches provided, in no event shall ARBOR Technology be liable for any direct, indirect, incidental, consequential, or special damages (including, without limitation, business interruption, loss of data, or lost profits) arising out of or in connection with the use, misuse, or reliance on the information, bulletins, or security fixes provided herein.

Users are solely responsible for testing and implementing security updates within their specific operating environments. ARBOR Technology reserves the right to amend, update, or withdraw this policy and security bulletins at any time without prior individual notice.