Product Security Policy

1. Appotronics Product Security Policy

 

Welcome to use the products and services of Appotronics. We attach great importance to product security and are committed to protecting your data security and privacy, ensuring that you can use our products safely and reliably. This Product Security Policy is designed to inform you about how we manage product - related security matters.

 

2. Product Security Philosophy 

 

Appotronics adheres to the philosophy of continuous innovation and strict control of security standards. Throughout the entire life cycle of product design, development, testing, and maintenance, we implement rigorous security measures to provide users with secure and reliable products. We actively adopt industry - leading security technologies and best practices to comprehensively protect products against various potential security threats. 

 

3. Security Vulnerability Management

 

(I) Security Issues Reporting

We encourage all users, partners, and security researchers to report any security vulnerabilities found during the use of Appotronics products. If you discover a potential security vulnerability, please contact us via the following email: globalservice@appotronics.com. When reporting a vulnerability, please provide as much detailed information as possible, including but not limited to:

 

1. The name, model, and version number of the product where the vulnerability was found.

2. If possible, please provide the specific scenarios and operation steps where the vulnerability occurred.

3.  A preliminary assessment of the possible impact of the vulnerability, such as the risk of data leakage, the possibility of system paralysis, etc.

 

(II) Security Issues Handling Procedure

Upon receiving your report regarding security vulnerabilities or issues, our professional team initiates the following processing procedure:

 

1.   Preliminary Assessment: Our team of security experts will conduct preliminary assessment of the report to determine its validity and severity in 3 days.

2.   Issue Investigation: If the report is confirmed as valid, we conduct an in-depth investigation to understand the specific causes and scope of the problem within 7 days.

3.   Solution Development: Based on the investigation results, our engineering team develops appropriate solutions, such as software updates or security patches to address identified vulnerabilities. In accordance with the severity classification of vulnerabilities, the remediation deadlines are defined as follows: 3 days for critical vulnerabilities, 30 days for medium-risk vulnerabilities, and 90 days for low-risk vulnerabilities.

4.   Testing and Verification: Before implementing any corrective measures, we conduct rigorous testing to ensure the effectiveness of the solution and prevent the introduction of new issues.

5.   Implementation and Notification: Once the solution is ready, we implement it through the appropriate channels and notify relevant users with detailed information about the updates.

 

 

(III) Our Commitment to Response

We commit to providing a response within 72 hours of receiving your information. Thank you for contributing to the enhancement of Appotronics product security.

 

4. Your Participation is Crucial

We appreciate your active participation; your reports directly contribute to improving the security of our products and safeguarding the interests of all users.

 

5. Maintaining Transparency and Communication

Throughout the entire processing, we are dedicated to maintaining transparency and communication with the reporter. We provide regular progress updates and release result reports to relevant stakeholders after resolving the issue.

 

6. Maintaining Transparency and Communication

Throughout the entire processing, we are dedicated to maintaining transparency and communication with the reporter. We provide regular progress updates and release result reports to relevant stakeholders after resolving the issue.

 

7. Legal Disclaimer

Thank you for choosing Appotronics and assisting us in ensuring the security of our products. We want to explicitly assure you that, regarding the security vulnerabilities or issues you report to us, you will not face any legal repercussions.

 

1.   Protection of Reporters: When you responsibly and lawfully report security issues, we commit not to take any legal action against you. We respect and protect the rights of contributors.

2.   Legitimate Reporting: We encourage you to discover and report security vulnerabilities within legal boundaries and in adherence to appropriate ethical standards.

3.   Compliance: Appotronics insists on compliance with all applicable laws and regulations, expecting reporters to similarly abide by relevant legal requirements.

4.   Confidentiality Agreement: For specific security issues, we may request reporters to sign a confidentiality agreement to protect the non-disclosure of technical details until the problem is adequately resolved.

 

8. Appotronics Product Security Update Assurance

To ensure continuous security protection for our users, Appotronics commits to providing long-term security update support for our products. The following are our assurances regarding product security updates:

Long-term Support: From the initial product release date, each product is guaranteed to receive security update support for at least the following durations. During this period, we will regularly review and address any issues that may affect product security.

Projector: 3 years

Interactive Display | Signage: 3 years

    • Update Frequency: Appotronics will periodically release security updates based on the specific needs of the product and changes in the security environment. Significant security threats will be prioritized.
    • Update Notifications: When new security updates are available, we will notify our users through appropriate channels such as the product interface, email, or our official website.
    • The Android security patch update depends on Google Policy. If the Android security patch is no longer updated within 3 years, related product cannot be updated for the Android security patch. For other update, we will follow our policy.
    • If the support period will be extended, the new defined support period will be published as soon as is practicable.

The defined support period will not shorten after the publication.

 

9. Appotronics Product Security Update Dates

* This list is constantly being updated and subject to change without notice.

 

xinghao-2.jpg