At Advanced Micro Controls Inc. (AMCI), the security and reliability of our products is important to us as an industrial automation supplier.
This Vulnerability Disclosure Policy describes how AMCI receives, tracks, investigates, assesses, remediates, and discloses security vulnerabilities affecting AMCI technologies, products, software, firmware, and services.
AMCI encourages customers, security researchers, partners, and other members of the security community to report potential vulnerabilities responsibly.
If you believe you have identified a security vulnerability in an AMCI product, software application, firmware, or service, please report the issue to AMCI via our security support team:
AMCI requests that vulnerability reports include as much of the following information as possible:
Providing complete and accurate information will help AMCI investigate and respond to the report efficiently.
AMCI reviews security vulnerability reports involving AMCI products and services.
Upon receiving a report, AMCI will make reasonable efforts to:
AMCI may involve engineering, product development, quality, technical support, manufacturing, and other appropriate internal or external resources during the investigation and remediation process.
AMCI evaluates confirmed vulnerabilities based on their potential impact on the confidentiality, integrity, and availability of affected products and systems.
Additional factors may include:
Where appropriate, AMCI may use industry-recognized vulnerability scoring methodologies, including the Common Vulnerability Scoring System (CVSS), to help communicate vulnerability severity and assist customers in assessing risk.
Because AMCI products may be used in industrial automation and operational technology environments, AMCI may also consider operational and system-level impacts when prioritizing remediation.
When AMCI confirms a security vulnerability, we will determine the most appropriate response based on the nature and severity of the issue.
Corrective actions may include:
AMCI will make reasonable efforts to provide customers with information necessary to understand affected products, available corrections, and recommended mitigation measures.
In some cases, particularly involving legacy or discontinued products, a firmware or software correction may not be technically feasible. In these cases, AMCI may provide alternative mitigation or security recommendations where appropriate.
AMCI supports coordinated vulnerability disclosure and recognizes the value of working collaboratively with security researchers and other parties who report potential vulnerabilities.
AMCI requests that individuals reporting vulnerabilities provide AMCI with a reasonable opportunity to investigate and address the issue before publicly disclosing technical details that could increase the risk to AMCI customers.
The appropriate timeframe for remediation and disclosure may vary depending on factors including:
AMCI will make reasonable efforts to coordinate disclosure with the reporting party when appropriate.
AMCI supports good-faith security research intended to identify and responsibly report potential vulnerabilities.
Researchers are encouraged to:
AMCI does not authorize activities that intentionally cause harm, disrupt systems or operations, compromise customer environments, access data without authorization, or otherwise violate applicable laws.
When appropriate, AMCI may publish a Product Security Advisory to provide customers with information regarding a confirmed security vulnerability.
Security Advisories may include:
AMCI may coordinate vulnerability disclosure with customers, security researchers, technology partners, suppliers, and other affected parties.
Industrial automation security requires a collaborative approach involving product manufacturers, machine builders, system integrators, customers, and operators.
AMCI encourages customers to follow applicable cybersecurity best practices, including:
Customers and system designers should evaluate cybersecurity risks as part of the overall design, installation, operation, and maintenance of industrial automation systems.
To report a potential security vulnerability affecting an AMCI product or service:
For general product support or technical assistance, please contact AMCI tech support.
AMCI may update this Vulnerability Disclosure Policy from time to time to reflect changes in our products, security practices, applicable standards, and regulatory requirements.
The most current version of this policy is available on this webpage.
Last Updated: September 2026