Vulnerability Disclosure Policy

AB Circle Limited (collectively, "AB Circle", "we", "us", "our") is committed to ensuring the security and integrity of our products with digital elements. This policy outlines our framework for security vulnerability reporting, response targets, and disclosure procedures for external security researchers, partners, and customers.

 

1. Purpose

This Vulnerability Disclosure Policy (VDP) explains how external parties may report suspected security vulnerabilities affecting AB Circle products containing digital elements. Reports received through our designated communication channels are triaged, investigated, and remediated under AB Circle’s internal Product Cybersecurity & Vulnerability Management Policy (PSV-001).

 

2. Scope

This policy applies to security vulnerabilities identified within:

  • AB Circle hardware products, firmware, software development kits (SDKs), drivers, and software.
  • Product interfaces, update mechanisms, and service tools.
  • Relevant third-party components integrated into AB Circle products.

Note on Transparency & Confidentiality: To maintain systemic security and comply with legal requirements, this public policy does not disclose internal triage evidence, Software Bill of Materials (SBOM) records, Common Vulnerabilities and Exposures (CVE) detailed analysis, exploitability analysis, or regulatory reportability decisions.

 

3. Reporting Channels

If you believe you have discovered a security vulnerability in an AB Circle product, please notify us through one of the following official channels:

  • Security Email: Send your detailed report to [email protected]. If this mailbox is unavailable, please contact AB Circle through our general support channels ([email protected]) and clearly mark the subject line as "Security Vulnerability Report."
  • Web Form: Use our designated Contact us page; otherwise, submit your report directly via the security email above.

 

4. Information to Include in Your Report

To help us verify and address the potential issue quickly, please include as much of the following technical details as possible:

  • Product Details: Product name, model, hardware version, firmware version, or software version affected.
  • Description: A detailed summary of the suspected vulnerability or security concern.
  • Reproduction Steps: Environmental conditions, configuration details, tools used, and step-by-step instructions required to reproduce the issue.
  • Impact Assessment: Potential impact on confidentiality, integrity, availability, access control, product operation, or user safety.
  • Supporting Evidence: System logs, technical observations, screenshots, or Proof-of-Concept (PoC) code where available.
  • Contact Information: Reporter name, organization (if applicable), and preferred contact details if you are willing to receive updates.

 

5. Good-Faith Guidelines

AB Circle values the contributions of the security research community. When conducting security research, we ask that you act in good faith and adhere to the following principles:

  • Avoid privacy violations, data destruction, service disruption, or unauthorized access to third-party systems.
  • Do not access, modify, delete, exfiltrate, or disclose data that does not belong to you or for which you lack explicit authorization.
  • Provide reasonable time for AB Circle to investigate, confirm, and remediate the issue before making any public disclosures.
  • Coordinate disclosure directly with AB Circle once the vulnerability has been confirmed and a fix is made available.

 

6. Response Targets

AB Circle strives to respond to security inquiries promptly. Our internal processes aim to meet the following target timelines:

Activity Target Timeline
Acknowledgement of Receipt Within 5 business days (where reporter contact details are provided).
Initial Triage Within 10 business days.
Progress Updates Periodically provided during active remediation, where appropriate.
Closure Communication Delivered following resolution, mitigation, final risk assessment, or documented no-action decision.

 

7. Coordinated Disclosure and Remediation

Confirmed vulnerabilities are evaluated based on risk severity, exploitability, technical feasibility, and customer impact. Depending on the nature of the issue, AB Circle may issue firmware/software updates, configuration guidance, product security advisories, release notes, or direct customer and distributor notifications. Public disclosures, when appropriate, will be coordinated responsibly.

 

8. Records and Internal Governance

AB Circle retains all vulnerability reports, technical assessments, remediation decisions, communications, and closure records in accordance with internal compliance standards and applicable legal/regulatory requirements. Detailed execution and operational handling are strictly governed under internal policy PSV-001 and its corresponding product annexes.

 

9. Questions and Enquiries

If you have general questions or concerns regarding this policy or AB Circle’s cybersecurity practices, please contact us at [email protected]

 

Last Updated: August 18, 2026