Insyde's Security Pledge

Report an Insyde Security Issue
Disclosure and Embargo Policy
If you believe you have found a vulnerability in an Insyde Software product, we encourage you to report the details to us. We will assign a member of our Office of Security and Trust to work with you during this process. We will acknowledge the report and give guidance on our future actions.
We will review your report and investigate the impact on our code. Usually within 7 business days, we will respond with the results of our studies. As a supplier, we provide services to many levels of the supply chains for complex products across many different industries. We request that you give us a minimum of 90 days to coordinate a disclosure plan with our partners. If the report leads to a public disclosure, this team member will provide the CVE ID to you with attribution if you desire. We thank you for your cooperation.
If you have information about a security issue or vulnerability with a product that may involve Insyde’s BIOS or BMC firmware, use Insyde Software’s SRT public PGP key (provided below) to send an encrypted e-mail and verify that security e-mails from Insyde Software are genuine.
Please send e-mails to security.report@insyde.com
- The products and versions affected
- Detailed description of the vulnerability
- Steps to demonstrate the vulnerability or reproduce the exploit, including specific configurations or peripherals, if relevant
- Potential impact of the vulnerability, when exploited
- Information on known exploits
Thank you for reporting your findings!
Key ID: 7D23A1242387829B (v4) User ID: Insyde Software <security.report@insyde.com> Fingerprint: F547EC8AB814091832B026F57D23A1242387829B Created: 2026-09-18 Expiration: 2028-12-31 17:54:21 Z -----BEGIN PGP PUBLIC KEY BLOCK----- xjMEaq16zRYJKwYBBAHaRw8BAQdAgnQkMGNXtiyDqPBWKhxQgwX+9N8DjGOa2aKxDdpvD2PNLElu c3lkZSBTb2Z0d2FyZSA8c2VjdXJpdHkucmVwb3J0QGluc3lkZS5jb20+woAEExYIACgCGQEFAmqt es0FCQRM1IACGwMECwkIBwYVCggJCwIDFgECAh4BAheAAAoJEH0joSQjh4Kb0VEA/jYaTmbdRoyY j4Jr9jE2Wov2pjudoC1sBifoXOK0uyg+AQCqZBIT/H4/socEFnGoQUpPjt5zjMBu1OnDcUdeZYSg As44BGqtes0SCisGAQQBl1UBBQEBB0DjZ/4NEEejl4FAGGy4t2uny2rbho+4+SDQIWVn6ePHAQMB CAfCbwQYFggAFwUCaq16zQIbDAQLCQgHBQkETNSAAh4BAAoJEH0joSQjh4KbfIEBAL6UieoK5ltL B/pulKCeRSJILwvjZxHN/QehLvvO3dNJAQCv6ZEGFoI4PfoQO6Xu/9hQfguWzmVBAKi0fnXkg6Tc Bw== =gJcg -----END PGP PUBLIC KEY BLOCK-----