Cybersecurity

Cybersecurity

 

AMCI VULNERABILITY disclosure POLICY

At Advanced Micro Controls Inc. (AMCI), the security and reliability of our products is important to us as an industrial automation supplier.

This Vulnerability Disclosure Policy describes how AMCI receives, tracks, investigates, assesses, remediates, and discloses security vulnerabilities affecting AMCI technologies, products, software, firmware, and services.

AMCI encourages customers, security researchers, partners, and other members of the security community to report potential vulnerabilities responsibly.

 

Report a Security Vulnerability

If you believe you have identified a security vulnerability in an AMCI product, software application, firmware, or service, please report the issue to AMCI via our security support team:

Contact AMCI Security

 

AMCI requests that vulnerability reports include as much of the following information as possible:

  • AMCI product name and part number
  • Hardware revision, if applicable
  • Firmware or software version
  • Description of the potential vulnerability
  • Conditions required to reproduce the issue
  • Step-by-step instructions to reproduce the vulnerability
  • Potential security impact
  • Proof-of-concept information, where appropriate
  • Any suggested mitigation or remediation

Providing complete and accurate information will help AMCI investigate and respond to the report efficiently.

 

AMCI Product Security Response

AMCI reviews security vulnerability reports involving AMCI products and services.

Upon receiving a report, AMCI will make reasonable efforts to:

  • Acknowledge receipt of the vulnerability report
  • Review and validate the reported issue
  • Assess the potential security and operational impact
  • Determine which products and versions may be affected
  • Investigate potential mitigations or corrective actions
  • Communicate with the reporting party when additional information is required
  • Coordinate disclosure when appropriate

AMCI may involve engineering, product development, quality, technical support, manufacturing, and other appropriate internal or external resources during the investigation and remediation process.

 

Vulnerability Assessment

AMCI evaluates confirmed vulnerabilities based on their potential impact on the confidentiality, integrity, and availability of affected products and systems.

Additional factors may include:

  • Ease of exploitation
  • Required level of access
  • Potential impact on industrial operations
  • Potential impact on machine or process availability
  • Safety considerations
  • Network exposure
  • Availability of mitigations or workarounds
  • Availability of software or firmware updates
  • Whether the vulnerability is known to be actively exploited

Where appropriate, AMCI may use industry-recognized vulnerability scoring methodologies, including the Common Vulnerability Scoring System (CVSS), to help communicate vulnerability severity and assist customers in assessing risk.

Because AMCI products may be used in industrial automation and operational technology environments, AMCI may also consider operational and system-level impacts when prioritizing remediation.

 

Vulnerability Remediation

When AMCI confirms a security vulnerability, we will determine the most appropriate response based on the nature and severity of the issue.

Corrective actions may include:

  • Firmware updates
  • Software updates
  • Product configuration changes
  • Product design changes
  • Documentation updates
  • Security guidance
  • Recommended mitigations or workarounds
  • Customer notifications
  • Security advisories

AMCI will make reasonable efforts to provide customers with information necessary to understand affected products, available corrections, and recommended mitigation measures.

In some cases, particularly involving legacy or discontinued products, a firmware or software correction may not be technically feasible. In these cases, AMCI may provide alternative mitigation or security recommendations where appropriate.

 

Coordinated Vulnerability Disclosure

AMCI supports coordinated vulnerability disclosure and recognizes the value of working collaboratively with security researchers and other parties who report potential vulnerabilities.

AMCI requests that individuals reporting vulnerabilities provide AMCI with a reasonable opportunity to investigate and address the issue before publicly disclosing technical details that could increase the risk to AMCI customers.

The appropriate timeframe for remediation and disclosure may vary depending on factors including:

  • Severity and potential impact
  • Exploitability
  • Availability of mitigations
  • Number of affected products or customers
  • Complexity of remediation
  • Safety or operational considerations
  • Third-party dependencies

AMCI will make reasonable efforts to coordinate disclosure with the reporting party when appropriate.

 

Good-Faith Security Research

AMCI supports good-faith security research intended to identify and responsibly report potential vulnerabilities.

Researchers are encouraged to:

  • Test only products and systems they own or are authorized to test
  • Use non-production or isolated environments whenever possible
  • Avoid disrupting customer operations or industrial processes
  • Avoid actions that could create safety risks
  • Avoid accessing, modifying, or deleting data that is not necessary to demonstrate the vulnerability
  • Avoid unnecessary exposure of sensitive information
  • Report vulnerabilities privately to AMCI before public disclosure

AMCI does not authorize activities that intentionally cause harm, disrupt systems or operations, compromise customer environments, access data without authorization, or otherwise violate applicable laws.

 

Security Advisories and Public Disclosure

When appropriate, AMCI may publish a Product Security Advisory to provide customers with information regarding a confirmed security vulnerability.

Security Advisories may include:

  • Description of the vulnerability
  • Affected products
  • Affected hardware, firmware, or software versions
  • Potential impact
  • Severity assessment
  • Available corrections
  • Mitigations or workarounds
  • Recommended customer actions
  • Relevant vulnerability identifiers, including CVE numbers where applicable

AMCI may coordinate vulnerability disclosure with customers, security researchers, technology partners, suppliers, and other affected parties.

 

Product Security Is a Shared Responsibility

Industrial automation security requires a collaborative approach involving product manufacturers, machine builders, system integrators, customers, and operators.

AMCI encourages customers to follow applicable cybersecurity best practices, including:

  • Keeping firmware and software current
  • Limiting network access to authorized users and systems
  • Using appropriate network segmentation
  • Avoiding unnecessary exposure of industrial devices to the public internet
  • Applying appropriate authentication and access controls
  • Monitoring systems and networks for unauthorized activity
  • Maintaining appropriate backups and recovery procedures

Customers and system designers should evaluate cybersecurity risks as part of the overall design, installation, operation, and maintenance of industrial automation systems.

 

Contact AMCI Product Security

To report a potential security vulnerability affecting an AMCI product or service:

Contact AMCI Security

 

For general product support or technical assistance, please contact AMCI tech support.



Policy Updates

AMCI may update this Vulnerability Disclosure Policy from time to time to reflect changes in our products, security practices, applicable standards, and regulatory requirements.

The most current version of this policy is available on this webpage.

Last Updated: September 2026

 

 

Save

Save

Save