Chat with us on WhatsApp!
SECURITY POLICY Product Vulnerability Responsible Disclosure

TOPICON Product Vulnerability Disclosure Policy

At TOPICON HK Limited, we prioritize security across our hardware platforms, customized Android operating systems, firmware, and connected services. We encourage security researchers and customers to report potential security vulnerabilities found in TOPICON products.

1. Scope of Products Covered

This disclosure program applies to security issues identified in:

Hardware & DevicesTOPICON Android Rugged Tablets
Firmware & OSCustom Android OS builds and firmware update mechanisms (OTA)
Software & Web PortalsTOPICON MDM and the official website (www.topicon.hk)

2. How to Report a Product Vulnerability

If you identify a security flaw in a TOPICON device or firmware, submit a detailed report to our engineering and security team:

Email: sales@topicon.hk

Subject: [Product Vulnerability Report] - [Short Description]

Required Details in Your Report

To assist our team in reproducing and patching the flaw, please include:

1. Target Hardware/OSDevice model, serial number, Android version, build/firmware version.
2. Vulnerability TypePrivilege Escalation, Bootloader Bypass, ADB/Debug Port Exposure, etc.
3. Reproduction StepsStep-by-step instructions, logs, or PoC code.
4. Impact AssessmentPotential risk, such as unauthorized access or device compromise.

3. Security Guidelines & Responsible Testing

To ensure safety during vulnerability research, especially when testing vehicle-mounted or fleet hardware, please adhere to these rules:

Rules of Engagement

Do Not Test on Active Vehicles

Always test on bench units or non-operational environments.

Avoid Physical Harm or Data Loss

No bricking or overwriting customer data without authorization.

Keep Disclosures Private

Allow time for patches before public release.

Prohibited Testing Actions

Do not conduct DoS attacks on infrastructure
Do not attempt social engineering or phishing
Do not distribute physical exploits without control

4. Triage & Remediation Timeline

Our engineering team handles product-level reports through a structured remediation workflow:

Phase
Target Timeline
Action
1. Initial Acknowledgment
Within 48 hours
Receipt confirmation and case assignment.
2. Technical Evaluation
Within 5 business days
Reproduce findings on target hardware.
3. Patch Development
Priority-Based
Security patch integrated into OS/OTA.
4. Customer Notification
Post-Fix
Distributed to affected clients and partners.

5. Recognition & Collaboration

Credit We will publicly credit researchers with their permission in advisories and patch notes.
Enterprise Coordination If vulnerabilities affect third-party chipsets or AOSP, we coordinate disclosure with upstream vendors.

Report a Security Vulnerability

Our engineering and security team reviews all submissions promptly. We value the contributions of security researchers and enterprise partners in keeping our products secure.

Email Us
sales@topicon.hk
Phone
+86 755 8254 9331
Location
Room 2314-2316, Tower C, Huangdu Plaza, Yitian Road, Futian, Shenzhen
Submit a Vulnerability Report

© 2026 TOPICON HK Limited | Product Security Policy v1.0