Coordinated Vulnerability Disclosure Policy | Atouch Winwel Lda

Atouch Winwel Lda is committed to the security of its products, software and digital services.

This Coordinated Vulnerability Disclosure Policy establishes the process through which security researchers, customers, partners and other entities may report potential vulnerabilities identified in Atouch products or services.

The objective is to ensure that such vulnerabilities can be analysed, corrected and, when necessary, disclosed in a responsible and coordinated manner, reducing the risk to users and affected systems.

1. Scope

This policy applies to products with digital elements made available under the Atouch brand and to components directly controlled by Atouch Winwel Lda, including, where applicable:

• Atouch mobile applications;

• Software developed by Atouch;

• Firmware;

• Gateways and other network connected devices;

• Software components directly maintained or controlled by Atouch.

Vulnerabilities existing exclusively in third party products or services that are not under Atouch’s control should be reported directly to the relevant provider.

Where a vulnerability in a third party component may affect an Atouch product, Atouch will assess the corresponding impact and, where necessary, coordinate the appropriate corrective and communication measures.

2. How to report a vulnerability

Any potential vulnerability related to an Atouch product or service may be reported through the following channels:

Email

info@atouch.com.pt

The following subject is recommended:

[SECURITY] Vulnerability

Support Line

+351 910 041 185

Contact Form

https://atouch.com.pt/contactos/

To enable a faster assessment, only the information necessary to identify, reproduce and evaluate the vulnerability should be provided.

Personal data, passwords, private keys, credentials or information belonging to third parties should not be submitted unless strictly necessary to demonstrate the issue.

3. Recommended information in the report

Whenever possible, the report should include:

  1. Affected product, model or application;
  2. Affected software or firmware version;
  3. Clear description of the identified vulnerability;
  4. Description of the observed behaviour;
  5. Steps required to reproduce the issue;
  6. Known or observed potential impact;
  7. Conditions required to exploit the vulnerability, for example local network access, authentication or user interaction;
  8. Proof of concept, screenshots, logs or other elements necessary for validation;
  9. Researcher contact details, if they wish to receive updates regarding the handling of the report;
  10. Information regarding any public disclosure already made or planned.

4. Responsible and good faith research

Atouch requests that any security research be conducted responsibly and limited to what is necessary to confirm the existence of the vulnerability.

During testing, researchers should:

• Use, whenever possible, equipment, accounts and environments they own or for which they have explicit authorisation;

• Stop testing if there is a risk of affecting the availability, integrity, confidentiality or security of other users;

• Avoid accessing, copying, modifying or deleting data belonging to third parties;

• Limit any access to the minimum necessary to demonstrate the vulnerability;

• Avoid any action that may cause interruption or degradation of services.

The following activities should not be carried out:

• Denial of service attacks;

• Destructive testing;

• Social engineering;

• Phishing;

• Unauthorised physical access attempts;

• Installation of malware;

• Installation of persistence mechanisms;

• Actions intended to maintain unauthorised access to systems;

• Use of the vulnerability for extortion, threats, personal gain or demands for compensation.

5. Atouch vulnerability handling process

After receiving a vulnerability report, Atouch will, where applicable, follow the process below:

  1. Receipt and registration of the report;
  2. Initial vulnerability triage;
  3. Confirmation of the product and potentially affected versions;
  4. Assessment of reproducibility and impact;
  5. Severity classification;
  6. Identification of potentially affected components and users;
  7. Definition of containment, mitigation or corrective measures;
  8. Development and testing of the correction;
  9. Preparation of a security update or mitigation instructions;
  10. Coordination of communication with the researcher and, where applicable, suppliers, customers, users or competent authorities;
  11. Closure of the process and retention of relevant evidence.

The complexity of each vulnerability may require different analysis and correction timeframes.

Atouch will seek to handle each report as quickly as possible, while always prioritising the security of users and affected products.

6. Coordinated disclosure

Atouch requests that technical details of a vulnerability that may facilitate its exploitation are not publicly disclosed before there has been a reasonable opportunity to analyse the issue and provide a correction or mitigation measure.

Whenever possible, the timing and content of any disclosure should be coordinated between Atouch and the researcher.

This coordination will take into account:

• The severity of the vulnerability;

• The risk to users;

• The existence of known exploitation;

• The availability of mitigation measures;

• The availability of a security update;

• The time required for users to apply the correction.

When a security update is available, Atouch may provide appropriate information regarding corrected vulnerabilities and the actions recommended to users.

Where immediate disclosure of technical details could significantly increase the risk of exploitation, such disclosure may be responsibly delayed.

7. Actively exploited vulnerabilities and severe incidents

Where Atouch obtains reliable evidence that a vulnerability is being maliciously exploited or identifies a severe incident affecting the security of a product, the applicable internal and legal procedures will be activated.

Where required under the Cyber Resilience Act, Regulation (EU) 2024/2847, Atouch will make the necessary notifications to the competent authorities through the applicable European mechanisms.

Whenever necessary, affected users will be informed about:

• The identified risk;

• Available mitigation measures;

• Recommended actions;

• Security updates that should be installed.

8. Personal data and confidentiality

Vulnerability reports should avoid including personal data or confidential information that is not necessary for the investigation.

The information received will only be made available to persons and entities that require access in order to:

• Analyse the vulnerability;

• Confirm the issue;

• Develop a correction;

• Implement mitigation measures;

• Comply with legal obligations;

• Communicate with the parties involved.

Where third party data is encountered during an investigation, any collection or access should be minimised and testing should stop as soon as the impact can be safely demonstrated.

9. Recognition and compensation

The existence of this policy does not constitute a vulnerability reward programme and does not imply any obligation to provide payment or financial compensation.

Where considered appropriate and with the researcher’s authorisation, Atouch may publicly acknowledge the responsible contribution of a person who reported a vulnerability after the issue has been corrected.

10. Legal notice

This policy provides a channel for the responsible reporting and coordinated handling of vulnerabilities.

It does not constitute authorisation to:

• Access systems, devices, accounts or data without authorisation;

• Carry out acts contrary to applicable law;

• Interfere with third party systems or services;

• Bypass security mechanisms for purposes not necessary to demonstrate the vulnerability;

• Carry out actions likely to cause damage to users, products or infrastructure.

Each researcher is responsible for ensuring that their testing complies with applicable law and with the authorisations available to them.

11. Updates to this policy

Atouch Winwel Lda may update this Coordinated Vulnerability Disclosure Policy whenever necessary, including due to:

• Legislative changes;

• Changes to products or services;

• Changes to internal procedures;

• New guidance from competent authorities;

• Evolution of cybersecurity best practices.

The version in force will always be the version published on the official Atouch website.

Last updated: September 2026