Responsible Disclosure Policy
Updated: 10 September 2026
As a leader in digital cinema solutions, GDC Technology is committed to ensuring the security of our products. We welcome the contributions of security researchers and the broader community in helping us identify potential vulnerabilities and security incidents in a private and responsible manner.
We would like to know about any vulnerability that you discover and encourage you to follow this guideline in reporting the same.
Scope
This policy applies to valid vulnerability issues discovered in products designed and manufactured by the GDC Technology. Please note that certain issues may not be considered valid vulnerability issues for the purpose of this policy, including but not limited to the following:
- Issues that are already publicly known or have been previously reported
- Configuration issues or deviations from best practice which do not directly affect security
- Scan reports from automated scanners or similar tools which have not been manually verified by a human to have a clear and direct impact on security
- Phishing, vishing, or other social engineering targeting employees or customers
- Vulnerabilities in third-party services or software integrated with our products.
This list is not exhaustive, and GDC Technology reserves the right to determine what constitutes a valid vulnerability issue.
Your Responsibilities
While we appreciate the efforts of the security community in identifying vulnerabilities, we request that you behave responsibly when identifying and disclosing the same. In particular, we request that you:
- Act in good faith, and report only genuine issues which you have verified to have an actual security impact.
- Conduct research ethically; avoid any malicious or destructive activities including service disruption, DoS/DDoS attacks, and social engineering.
- Limit testing to what is strictly necessary to confirm the vulnerability. Do not access, modify, or delete sensitive or confidential data beyond what is necessary to demonstrate a minimal proof of concept.
- Do not exploit the vulnerability or engage in extortion.
- Report the vulnerability to us immediately, in accordance with the reporting process below, and provide our team with reasonable time to respond and address the issue.
- Do not share details about the vulnerability with third parties or the public, until our team has released a corrective patch or otherwise taken remedial action to minimize the risk.
Reporting Process
- Please report the vulnerability issue by e-mail to [email protected].
- The report should be in English and include a detailed description of the vulnerability issue, an evaluation of the potential security impact, and step-by-step instructions on how to reproduce the issue.
- Please also include your contact information, so that our team can reach out to you for further information as necessary. Your personal information shall be kept strictly confidential, and shall not be shared with third parties without your permission.
GDC Technology will endeavour to confirm receipt of your report and investigate the issue in a timely manner. However, please note that some issues may require more time to analyse. Your patience and understanding are much appreciated.
Once a vulnerability is verified and remediated, and the solution is ready for public release, GDC Technology will publish a formal security advisory on our dedicated security portal, www.gdc-tech.com/security-advisories, to help users keep their systems secure.
GDC Technology will not initiate civil or criminal legal action against you for conducting the security research which resulted in the report, provided that you conduct your research in good faith and in strict adherence to your responsibilities outlined in this policy. However, we reserve the right to take such action as we deem appropriate if you violate this policy, or otherwise engage in malicious or illegal activities.
Please note that GDC Technology currently does not operate a “bug-bounty programme” or otherwise offer any reward for identifying bugs or vulnerabilities.
Changes to this Policy
GDC Technology reserves the right to modify, amend, or update this responsible disclosure policy at any time. Any changes will be posted directly to this page with an updated effective date. We encourage you to check this policy periodically for updates.