Contacts

Head Office

8F., No.55, Nanxing Road, Xizhi District, New Taipei City, 221, Taiwan

Tel +886-2-8646-2111
Email info@axiomtek.com.tw

Sales and Quotation

Thank you for your interest in Axiomtek. For faster assistance, please complete the inquiry form for product information or a quote.

Security Policy

Coordinated Vulnerability Disclosure (CVD) Policy

Axiomtek follows Coordinated Vulnerability Disclosure principles. We commit to acknowledging receipt of vulnerability reports within 2 business days (48 hours). Disclosure timelines are agreed upon with reporters in accordance with ISO/IEC 29147 principles.

How to Report a Vulnerability

Encryption Key Download PGP Key

Safe Harbor: Axiomtek will not initiate legal action against security researchers who conduct vulnerability research in good faith and comply with this policy.

Reporting Obligations

As required by the EU Cyber Resilience Act (CRA), mandatory vulnerability and incident reporting obligations apply from 11 September 2026. Axiomtek reports actively exploited vulnerabilities and severe incidents through the EU Single Reporting Platform (SRP), enabling simultaneous notification to the designated CSIRT coordinator and ENISA.

Stage 1

Early Warning

Initial notification submitted without undue delay and within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.

Stage 2

Incident Notification

Further notification submitted within 72 hours, providing available technical information, an initial assessment, and corrective or mitigating measures.

Final

Final Report

For actively exploited vulnerabilities, the final report is submitted no later than 14 days after a corrective or mitigating measure becomes available. For severe incidents, the final report is submitted within one month after the incident notification, detailing the impact, corrective measures, and resolution status.