GIGABYTE Coordinated Vulnerability Disclosure Policy
GIGABYTE Coordinated Vulnerability Disclosure Policy
Version: 1.0
Effective Date: September 1, 2026
Last Updated: September 1, 2026
GIGABYTE Technology Co., Ltd. (“GIGABYTE”) is committed to the security of our products and services and to providing our customers with secure and reliable products.
We recognize the important role that security researchers, customers, partners, and the broader security community play in helping improve product security. GIGABYTE supports the principles of Coordinated Vulnerability Disclosure (CVD) and encourages the responsible, good-faith reporting of potential security vulnerabilities.
By working collaboratively with researchers, we aim to validate reported vulnerabilities, assess their potential impact, develop appropriate fixes or mitigations, and coordinate disclosure in a manner that helps protect customers and the broader ecosystem.
1. Scope
This Policy applies to GIGABYTE-branded products and related digital components that are provided or maintained by GIGABYTE Technology Co., Ltd., including, but not limited to:
- GIGABYTE-branded hardware products;
- BIOS, UEFI, BMC, firmware, and other product firmware;
- drivers, utilities, and product-related software; and
- digital services provided by GIGABYTE that are directly related to product functionality or product security.
Where a reported vulnerability affects a third-party component, open-source software, chipset, firmware, or other supplier technology, GIGABYTE may coordinate with the relevant supplier, maintainer, or vulnerability coordination organization as appropriate.
Products, services, or systems operated by affiliates, other brands, or third parties, or that are not maintained by GIGABYTE Technology Co., Ltd., may fall outside the scope of this Policy.
GIGABYTE may still accept vulnerability reports concerning products that have reached the end of their support lifecycle. However, investigation, remediation, or other actions for such products will be evaluated on a case-by-case basis.
2. Reporting a Security Vulnerability
If you believe you have identified a security vulnerability affecting a GIGABYTE product or service, please report it to the GIGABYTE Product Security Incident Response Team (PSIRT) through the following channels:
Security Contact: PSIRT@gigabyte.com
Security Advisory: https://www.gigabyte.com/security/vulnerability-disclosure-policy
PGP Public Key: https://www.gigabyte.com/pgp-key.asc
Security Advisory: https://www.gigabyte.com/security/security-advisory
Security.txt: https://www.gigabyte.com/.well-known/security.txt
If your report contains sensitive technical information, proof-of-concept code, credentials, personal data, or other confidential information, we recommend encrypting the report using GIGABYTE's published PGP Public Key.
Please refer to the GIGABYTE website or our security.txt file for the latest product security contact and encryption information.
3. Information to Include in Your Report
To help us investigate and respond efficiently, please provide as much of the following information as possible:
- the affected product name and model;
- the affected BIOS, firmware, driver, software, or other relevant version;
- a clear technical description of the vulnerability and its potential security impact;
- the environment, conditions, and detailed steps required to reproduce the issue;
- proof-of-concept (PoC) code or other supporting technical information, where applicable;
- known attack scenarios or conditions required for exploitation;
- whether you are aware of the vulnerability being actively exploited;
- whether the vulnerability has also been reported to another vendor, CNA, CERT/CSIRT, or other coordination organization;
- any planned public disclosure date; and
- an email address or other contact information through which GIGABYTE may follow up with you.
You may submit a report using your legal name, researcher identity, alias, or other identifier.
Please note that if you do not provide contact information, our ability to request additional information or provide updates regarding the investigation may be limited.
Please do not submit passwords, private keys, personal data, or other sensitive information that is not reasonably necessary to validate the vulnerability through unencrypted channels.
4. Guidelines for Responsible Security Research
GIGABYTE appreciates the efforts of security researchers who help us improve the security of our products and services.
When conducting security research or validating a potential vulnerability, we ask that you:
- limit testing to what is reasonably necessary to demonstrate or validate the vulnerability;
- make reasonable efforts to avoid disrupting the normal operation of products, services, systems, or networks;
- do not access, download, modify, delete, destroy, or misuse data without authorization;
- do not conduct denial-of-service (DoS), distributed denial-of-service (DDoS), or other destructive testing;
- do not conduct social engineering or phishing against GIGABYTE employees, customers, or partners;
- do not install malware, establish persistent access, or retain access beyond what is reasonably necessary to validate the vulnerability;
- do not use a vulnerability for fraud, extortion, financial gain through improper means, or any other unlawful purpose;
- make reasonable efforts to avoid violating the privacy or rights of GIGABYTE, our customers, or third parties;
- allow GIGABYTE a reasonable opportunity to investigate, remediate, or mitigate the vulnerability before public disclosure; and
- coordinate with GIGABYTE before publicly disclosing technical information that could enable exploitation of the vulnerability.
All security research must comply with applicable laws and regulations.
5. Vulnerability Handling and Coordination Process
After receiving a vulnerability report, GIGABYTE PSIRT will evaluate and handle the report based on the nature and risk of the vulnerability. Where appropriate, GIGABYTE uses the Common Vulnerability Scoring System (CVSS) as part of its vulnerability severity assessment.
Acknowledgment
GIGABYTE will make reasonable efforts to acknowledge receipt of a valid product security vulnerability report within three business days.
If additional information is required to analyze or reproduce the reported issue, we may contact the reporter for further details.
If requested information is not provided within 30 days, GIGABYTE may close the report. A closed report may be reopened if sufficient information is subsequently provided.
Validation and Risk Assessment
As appropriate, GIGABYTE PSIRT will work with relevant product, engineering, and security teams to:
- validate and reproduce the vulnerability;
- identify affected products and versions;
- assess potential security impact and exploitability;
- determine vulnerability severity;
- perform root-cause analysis; and
- evaluate the overall security risk.
Remediation and Mitigation
For confirmed vulnerabilities, GIGABYTE will determine appropriate actions based on the assessed risk and product circumstances.
Such actions may include:
- BIOS, firmware, driver, or software updates;
- security patches;
- configuration changes;
- workarounds or mitigations;
- security guidance for users; or
- coordinated remediation with third-party component suppliers.
Where a vulnerability involves third-party components or affects multiple vendors, GIGABYTE may coordinate with relevant suppliers, CVE Numbering Authorities (CNAs), CERTs/CSIRTs, or other appropriate vulnerability coordination organizations.
6. Coordinated Disclosure and Security Advisories
GIGABYTE will consider the severity of the vulnerability, affected products, remediation status, customer risk, and coordination requirements with relevant suppliers or other parties when determining an appropriate disclosure timeline.
To reduce the risk of exploitation before users have an opportunity to apply appropriate protections, we ask researchers not to publicly disclose detailed technical information or exploit code that could enable reproduction or exploitation of the vulnerability until the coordinated disclosure process has been completed.
When a confirmed vulnerability requires customer action, GIGABYTE may publish information through a GIGABYTE Security Advisory or other appropriate communication channels.
Depending on the circumstances, a Security Advisory may include:
- a CVE Identifier;
- a description of the vulnerability;
- affected products and versions;
- vulnerability severity and security impact;
- remediation or updated versions;
- workarounds or mitigation measures;
- recommended customer actions;
- publication and revision dates; and
- acknowledgment of the security researcher.
In certain circumstances, GIGABYTE may delay publication of specific technical details where immediate disclosure could materially increase the risk to customers before appropriate fixes or mitigations can be deployed.
7. Remediation Timelines and Communication
The time required to validate, assess, and remediate a vulnerability may vary depending on factors such as:
- vulnerability complexity and severity;
- the number of affected products and versions;
- differences in hardware, firmware, and software architectures;
- development, validation, compatibility, and quality testing requirements;
- dependencies on third-party components or suppliers;
- CVE coordination or multi-vendor coordinated disclosure; and
- embargoes or other vulnerability disclosure arrangements.
Accordingly, except where expressly stated otherwise in this Policy, GIGABYTE does not commit to a fixed remediation timeline for any specific vulnerability.
During the investigation, GIGABYTE will make reasonable efforts, where appropriate and practicable, to communicate material case updates to the reporter.
8. Safe Harbor for Good-Faith Security Research
GIGABYTE supports good-faith security research intended to improve the security of our products and services.
To the extent permitted by applicable law, GIGABYTE will not initiate legal action solely on the basis of security research conducted in good faith and in accordance with this Policy, provided that the researcher:
- acts in good faith for legitimate security research purposes;
- complies with the guidelines set out in this Policy;
- limits testing to what is reasonably necessary to validate the vulnerability;
- takes reasonable measures to avoid harm to GIGABYTE, our customers, or third parties; and
- reports the vulnerability to GIGABYTE in accordance with this Policy and participates in reasonable coordinated disclosure efforts.
This Safe Harbor does not apply to:
- malicious, fraudulent, extortionate, or otherwise unlawful activity;
- intentional damage to products, systems, services, or data;
- unauthorized acquisition, use, or disclosure of data;
- DoS, DDoS, or other activities that impair service availability;
- social engineering or phishing; or
- activities that clearly exceed what is reasonably necessary for legitimate security research or vulnerability validation.
This Policy applies only to products and systems that GIGABYTE has the authority to manage or authorize for testing.
GIGABYTE cannot authorize security research involving products, services, systems, networks, or infrastructure owned, operated, or controlled by third parties.
9. CVE Assignment, Researcher Recognition, and Rewards
Depending on the nature of the vulnerability and the circumstances of the case, GIGABYTE may obtain a CVE Identifier directly or in coordination with an appropriate CVE Numbering Authority (CNA) or vulnerability coordination organization.
With the reporter's consent and where GIGABYTE considers it appropriate, we may publicly acknowledge the security researcher or organization in the relevant Security Advisory.
Researchers may also choose to remain anonymous or use a preferred researcher identity.
Unless GIGABYTE has separately announced an official Bug Bounty Program or other security research reward program, this Policy does not constitute a commitment to provide any monetary reward, compensation, or other payment for vulnerability reports.
10. Privacy and Use of Information
Contact information and other information submitted to GIGABYTE in connection with a vulnerability report will be used primarily for purposes including:
- vulnerability validation and technical analysis;
- communicating with the reporter;
- remediation and security risk management;
- coordinated vulnerability disclosure;
- security advisories and related coordination; and
- compliance with applicable legal and regulatory requirements.
GIGABYTE will handle such information in accordance with applicable data protection, privacy, and information security requirements.
11. Disclaimer
This Policy describes GIGABYTE's general approach and procedures for coordinated vulnerability disclosure and product security vulnerability handling.
It does not create any express or implied warranty, contractual obligation, service level agreement (SLA), or commitment to a specific outcome.
The time required to validate, assess, remediate, and disclose a vulnerability may vary depending on the complexity of the vulnerability, affected products, third-party dependencies, supplier coordination, validation and testing requirements, embargo arrangements, and other relevant circumstances.
GIGABYTE may update or adjust this Policy and its related processes as appropriate in response to security risks, product circumstances, industry practices, or applicable legal and regulatory requirements.
Nothing in this Policy authorizes unlawful, unauthorized, destructive, or otherwise harmful activity affecting GIGABYTE, our customers, third parties, or their respective systems, services, data, or rights.
Nothing in this Disclaimer is intended to exclude, restrict, or otherwise affect any obligation imposed on GIGABYTE under applicable mandatory laws or regulations.
12. Policy Updates and Contact Information
GIGABYTE may update this Policy from time to time in response to changes in our products, the threat landscape, industry practices, or applicable legal and regulatory requirements.
The current version of this Policy will be published on the official GIGABYTE website.