TWSE: 8072 · Est. 1996 · Taipei, TaiwanEN · 繁中 · 日本語
Security & Trust Center

Trust is a document, not a slogan.

Surveillance equipment guards other people's property; it has to be trustworthy itself. This page collects everything we publish about how our products are built, signed, and fixed — so you can verify rather than assume.

Supply-chain compliance

NDAA §889 / TAA

Per-shipment declarations

Every compliant product ships with a declaration backed by a maintained component-origin register. Auditors may request the underlying BOM documentation under NDA.

Origin

Designed & made in Taiwan

Hardware and firmware engineering in Taipei; SMT and assembly in our group facility in Taiwan. No design, code, or manufacturing dependencies on entities named in §889.

Certifications

Market approvals

CE, FCC, and BSMI certifications maintained per product line, with additional market-specific approvals handled per OEM program.

Product security engineering

PracticeWhat it means for you
Signed firmwareDevices verify firmware signatures before install. Updates are distributed only through official channels listed under Support.
SBOMA software bill of materials is generated for release firmware and available to OEM partners and enterprise customers on request.
Encrypted transportHTTPS device management; SIP over TLS with SRTP media on access products; SRTP options on camera streams.
Hardening guidesDeployment hardening documentation for integrators — default-credential elimination, network segmentation, and update policy.
Vulnerability responseA published intake channel, acknowledgement targets, and public advisories. See PSIRT below.

PSIRT — report a vulnerability

We treat every good-faith report as a gift. If you believe you have found a security issue in an AVTECH product, tell us directly and we will work with you on a coordinated disclosure.

How to report

security@avtech.com.tw

Include the product model, firmware version, and reproduction steps. PGP key available on request. We acknowledge reports within 3 business days and aim to provide a remediation plan within 30 days for confirmed issues. We do not pursue legal action against good-faith research.

Our commitment

Fix, publish, credit

Confirmed vulnerabilities receive a public advisory with affected versions and fixed firmware, and reporters are credited unless they prefer otherwise. Advisories are listed below and announced through partner channels.

Security advisories

CVE-2024-7029 — command injection in a discontinued camera model (end-of-life since 2017). Reported via CISA; observed exploited in the wild. Despite EOL status, AVTECH released fixed firmware for affected users. Recommendation: update immediately and never expose device management interfaces directly to the internet.FIXED · FIRMWARE ISSUED
Further advisories — published as issuedAVTECH-SA-YYYY-NNN
Subscribe to advisory notifications via your AVTECH sales or support contact.RSS planned

Auditing a supplier? Start here.

We would rather answer your security questionnaire before the purchase order than after an incident. Compliance documentation and factory audits are available to qualified partners.