Vulnerability Disclosure Policy
Hanshow is committed to protecting the security of our products, services, and customer data. We welcome responsible security researchers and partners to help us identify and resolve potential vulnerabilities.
Found a Security Issue?
You can report vulnerabilities without logging in. Our security team will review your submission and provide updates throughout the process.
security@hanshow.com
Scope of This Policy
Web Applications
Corporate websites and customer-facing web applications operated by Hanshow.
Software Services
Platforms, software services, APIs and related digital solutions.
Product Software
Software components supporting Hanshow products and solutions.
Cloud Services
Cloud-based services operated and managed by Hanshow.
Vulnerability Classification
Critical
30 Days
Major security impact including unauthorized access, data exposure or remote code execution.
High
60 Days
Unauthorized access, privilege escalation or sensitive information exposure.
Medium
90 Days
Issues requiring specific conditions or user interaction.
Low
180 Days
Security weaknesses with limited practical impact.
Vulnerability Handling Process
Submission
Receive vulnerability reports.
Assessment
Evaluate impact and severity.
Planning
Define remediation solution.
Fix
Implement and verify solutions.
Report
Publish updates when appropriate.
Contact Hanshow Security Team
For security vulnerability reports:
security@hanshow.com