Haitian PSIRT

To promptly identify and appropriately address potential security vulnerabilities in its products and services, mitigate security risks, and protect the information and business security of users and relevant parties,we have established a Product Security Incident Response Team (PSIRT) to receive security vulnerability reports submitted by external security researchers, partners, and users, and to coordinate the verification of vulnerabilities, risk assessments, remediation, and the necessary coordination of vulnerability disclosures and security advisories.

Vulnerability Reporting

If you discover a potential security vulnerability in Haitian’s products or services, please contact us at the following email addresses: ht-psirt@mai.haitian.com
To help us quickly verify and identify the issue, we recommend providing the following information whenever possible:

Name, model, and software/firmware version of the affected product;
Type and description of the vulnerability, steps to reproduce it, or relevant technical details;
Potential impact of the vulnerability;
Whether the vulnerability has been publicly disclosed or is being actively exploited;
Planned disclosure date (if applicable);
Contact information (if you wish to provide it)

Upon receiving a vulnerability report, we will acknowledge it as soon as possible and maintain necessary communication with the reporter based on the progress of verification and resolution. Given the sensitivity of vulnerability information, we recommend sending sensitive information via secure methods, such as encrypted compressed files.

Vulnerability Handling and Response Process

Upon receiving a vulnerability report, the PSIRT will verify the details, conduct a risk assessment, and take appropriate action based on the nature of the vulnerability, while coordinating with the relevant product and R&D teams to implement fixes and perform validation.

Vulnerability Submission → PSIRT Receipt and Acknowledgment → Vulnerability Analysis → Risk Assessment → Fix and Remediation → Security Verification → Closure / Security Advisory

Vulnerability handling will be conducted in accordance with applicable laws and regulations and the company’s internal product vulnerability management process.

Code of Conduct for Security Research

When conducting vulnerability research, please avoid disrupting normal business operations and refrain from DoS/DDoS testing, bulk retrieval/modification/deletion of data, social engineering, or phishing tests. If you inadvertently come into contact with personal information or sensitive data, please immediately cease further access and note this in your report. Please do not disclose technical details that could increase security risks until the vulnerability has been fixed or disclosure arrangements have been coordinated.

Security Advisory

For confirmed product security vulnerabilities that require public disclosure, we will issue a security advisory as appropriate once security updates, fixes, or mitigation measures become available. The advisory will detail the vulnerability description, affected products and versions, the impact and severity of the vulnerability, fixes or mitigation measures, and relevant security update information.

! There are currently no public security vulnerability advisories.

This page is primarily used to receive product security vulnerability reports and publish related security bulletins. If you are experiencing an ongoing security incident or require urgent product support, please contact Customer Support while submitting the relevant security information.

Privacy Notice: The information you submit through this page will be used solely to process and respond to vulnerability reports, maintain vulnerability records, and fulfill relevant obligations under applicable laws and regulations. For information regarding the retention period of personal information, your relevant rights, and privacy contact information, please refer to the [Privacy Policy]. Except for necessary contact information, you are not required to provide identifying information such as your name or organization.