BIOSTAR (the "Company", "we") values product security and welcomes good-faith reports of security vulnerabilities in our products from security researchers and any third party ("reporters"). We commit to handling reports in a timely manner under this policy, coordinating disclosure with reporters, and providing the safe harbor protections in Section 6 for good-faith research that complies with this policy.
This policy applies to the following Company products, including their software and firmware:
All products currently listed on our official website, including their software and firmware: motherboards (consumer and industrial), EdgeComp edge computing systems, graphics cards, solid-state drives, memory modules, and the BIOS/UEFI firmware, drivers, applications, and update utilities supplied with them.
The following activities are not within the scope (authorization) of this policy:
- Denial-of-service (DoS/DDoS) or stress testing against systems of the Company or any third party
- Social engineering, phishing, or impersonation targeting Company personnel
- Physical intrusion, theft, or destruction
- Testing of third-party services, cloud platforms, or upstream supplier systems not operated by the Company
- Large-scale automated scanning that degrades service quality
Reporting mailbox:
[email protected]
This reporting channel is operated with the assistance of ICSDA, Taiwan (icsda.org.tw).
Where possible, please include: affected product and version, vulnerability type and steps to reproduce (PoC), impact assessment, your preferred disclosure approach, and whether you wish to be credited or remain anonymous. Anonymous reports are accepted. Reports may be submitted in Chinese or English.
Stage
Timeline
Description
Acknowledgement
Immediately upon receipt (automated)
Case number and a link to this policy
Initial response
Within 3 business days
Staff review the report and request further details if needed
Status updates
At least every 14 days
Progress updates until the case is closed
Remediation target
Case-by-case, based on severity
Remediation, update release, and (where applicable) a security advisory
Criteria for good-faith research
Research and reporting activities that satisfy all of the following constitute "good-faith research" under this policy:
- Conducted solely to discover and report vulnerabilities, without exceeding the minimum scope necessary to verify that a vulnerability exists
- No destruction, alteration, or deletion of any data; no impact on the availability of any system; no installation of persistent-access mechanisms
- Where contact with others' data is unavoidable for verification, such contact is limited to the minimum necessary; the data is not copied, retained, or distributed, and is deleted after reporting
- No use of vulnerability information for extortion, threats, sale, or any other unlawful purpose
- No disclosure of vulnerability details to any third party before the coordinated disclosure date
- Compliance with the scope restrictions in Section 2 of this policy
The Company's commitments
For good-faith research that satisfies the above:
- We regard it as security testing authorized by the Company and will not assert that it violates our terms of service or license terms.
- To the extent permitted by law, we commit not to initiate civil proceedings, file criminal complaints or referrals, or claim damages in respect of such good-faith research.
- The rights of third parties (including our upstream suppliers and other affected vendors) are not ours to waive; activities involving third-party systems or rights fall outside this safe harbor.
- If you are unsure whether your activities comply with this policy, please contact us first; we will respond within 3 business days.