Corporate Responsibility

 

ATP Social Responsibility Policy Statement

 

View our Social Responsibility Statement

 

ATP Supplier Ethical Commitment

 

ATP Electronic, Inc and its affiliates (ATP) are committed to the highest standards of product quality and business integrity. ATP requires all of its suppliers and employees to conduct themselves with the highest standards of honesty, fairness, and integrity, complying with all applicable laws and avoiding even the appearance of impropriety.

ATP expects all employees, customers, partners, suppliers, shareholders, and stakeholders to speak up promptly about any conduct or circumstances they believe may constitute a violation of this Supplier Ethics Policy or any other ATP policy. Supplier shall promptly notify the ATP Ethics Office at ethics@tw.atpinc.com regarding any known or suspected illegal or improper behavior relating to dealings with or on behalf of ATP, including behavior by ATP’s employees or agents.

View ATP's Supplier Ethical Commitment

 

Environmental Sustainability

 
Greenhouse Gas Emissions

View Scope and Amount of Greenhouse Gas Emissions

 
Statement on Conflict Metals

 

Gold (Au), tantalum (Ta), tungsten (W) and tin (Sn) are commonly used in the electronics industry. These elements come from a variety of sources, including what is referred to as "Conflict Zones," which includes the eastern region of the Democratic Republic of the Congo (DRC).

As a manufacturer of products that contain gold, tantalum, tungsten and tin, which are considered conflict minerals, ATP is committed to sourcing these materials only from socially and environmentally responsible suppliers.

We’re taking steps across our entire supply chain to confirm our sourcing does not fund armed groups in the DRC and adjoining countries.  We continue to carry out a reasonable country of origin inquiry on the products we manufacture and perform supply chain due diligence following the processes and procedures set forth in the Organization for Economic Co-operation and Development’s Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas.

ATP expects our suppliers to adhere to the Responsible Business Alliance (RBA) Code of Conduct, formerly known as the Electronic Industry Citizenship Coalition® Code of Conduct (www.responsiblebusiness.org/), to source materials responsibly and not knowingly use metals originating from Conflict Zones.

 
RoHS Compliance Statement

 

The Restriction of Hazardous Substances (RoHS) Directive (2011/65/EU) restricts the use of certain hazardous substances commonly used in the manufacturing of electronic equipment and requires producers of electronic equipment to reduce the concentration of these hazardous materials, which include:

  • Cadmium (Cd) ‹ 100 ppm
  • Lead (Pb) ‹ 1000 ppm
  • Mercury (Hg) ‹ 1000 ppm
  • Hexavalent Chromium (Cr VI) ‹ 1000 ppm
  • Polybrominated Biphenyls (PBB) ‹ 1000 ppm
  • Polybrominated Diphenyl Ethers (PBDE) ‹ 1000 ppm

Commission Delegated Directive (EU) 2015/863 of 31 March 2015 amends Annex II to Directive 2011/65/EU of the European Parliament and of the Council with the addition of four phthalate substances to the list of restricted substances. The following will be internally restricted effective 22 July 2019.

  • Bis(2-Ethylhexyl) phthalate (DEHP) ‹ 1000 ppm
  • Benzyl butyl phthalate (BBP) ‹ 1000 ppm
  • Dibutyl phthalate (DBP) ‹ 1000 ppm
  • Diisobutyl phthalate (DIBP) ‹ 1000 ppm

ATP products comply with the EU RoHS Directive.

 
China RoHS Compliance

 

China RoHS is similar to its European counterpart in that it prohibits the use of heavy metals (Lead, Mercury, Cadmium, Hexavalent Chromium) and two brominated compounds (Polybrominated Biphenyls and Polybrominated Diphenyl Ethers). China RoHS differs in having two phases, having no exemptions, requiring marking of product to show compliance, and requiring testing of product to show conformity in implementing the second phase.

ATP is fully committed to environment protection and sustainable development and has set in place a comprehensive program, in conjunction with our customers and suppliers, for removing polluting and hazardous substances from all of its products where this is technically feasible.

 
REACH Compliance Statement

 

REACH (Registration, Evaluation, Authorization and Restriction of Chemicals) is an EU Regulation that came into force on 1 June 2007. It aims to protect human health and the environment from the risks of chemicals.

ATP is committed to meeting all REACH requirements and providing our customers with information about the chemical substances in our products according to REACH regulations. All our products are articles according to the definition of REACH regulation.

For REACH Article 33 declaration, please contact the concerned branch of ATP Electronics Inc.

 
Waste Electrical and Electronic Equipment (WEEE)

 

The 2013 Waste Electrical and Electronic Equipment (WEEE) Regulations became law in the UK on 1 January 2014. It replaced the 2006 WEEE Regulations.

The Regulations, which refer to the EU Directive 2012/19/EU, restrict the use of hazardous substances in electrical and electronic equipment and set targets for the collection, recovery and recycling of WEEE. Producers placing products into the EU market are obliged to identify equipment suitable for recycling and allow it to be separated from other waste streams. The "crossed out wheelie bin" symbol with a black bar beneath it denotes that the product falls within these WEEE directive guidelines and should either be printed directly on the product or within the user documentation. As a WEEE producer, ATP Electronics Inc. must support its market share proportion of the financial burden of the collection, treatment and recycling of EEE products, and is legally required to register with the Environment Agency (EA) directly or via the Producer Compliance Scheme (PCS).

 

Coordinated Vulnerability Disclosure (CVD) Policy

 
1. Purpose:
At ATP, we prioritize product security as our top concern. However, no matter how much effort we invest in product security, vulnerabilities may still exist. If you discover any vulnerability, we would appreciate it if you could report it to us so that we can take prompt action to address it, helping us continuously improve product security and safeguard our users' privacy and data.
 
2. Scope:
This Policy applies to all products sold by ATP.
 
3. Reporting Process:
(1) If you have identified a potential vulnerability, please follow the instructions below:
Please submit your findings via email to “ATP_Security@tw.atpinc.com”. To protect sensitive information, please use our PGP public key (Link) to encrypt your submission.
We respectfully ask that you refrain from exploiting the identified vulnerability or security issue you discovered, including any unauthorized access, data collection, or other conduct that may affect the system, service, or users, such as downloading more data than is necessary to validate the vulnerability, or deleting or modifying data belonging to other users.
Before the vulnerability has been resolved (i.e., the fix has been completed and the vulnerability has been publicly disclosed, or the disclosure has been approved by ATP, please do not disclose any information or PoC related to the vulnerability to any third party. (Please refer to the table below for the committed timeline)
Do not conduct any physical security attacks, social engineering, denial-of-service attacks, spam, or attacks against third-party applications.
o Conduct testing only to the minimum extent necessary to verify the vulnerability, and do not perform in-depth testing unrelated to vulnerability verification.
o Do not access, modify, delete, download, or disclose any sensitive information or business data that does not belong to you.
o Do not conduct destructive activities, including DoS/DDoS attacks, social engineering, physical attacks, malicious persistence, ransomware attacks, or lateral movement.
o Do not conduct any testing that may affect the stability of the production environment or the availability of services.
o Do not disclose vulnerability details or other sensitive information to any third party before the vulnerability handling process has been completed.
To assist us in validating and reproducing the vulnerability, please provide sufficient information, including but not limited to:
o Information about the affected product (e.g., product number or model); and
o A description of the vulnerability and the steps to reproduce it.
If further information is required for confirmation or to address complex vulnerabilities, we may contact you. Please keep an eye on your email and feel free to contact us at any time.
(2) Our Commitments:
Within seven (7) business days following receipt of your report, we will send you an email confirming receipt and outlining the subsequent handling process.
We will handle your report with strict confidentiality and will not disclose your personal information to any third party without your prior written consent, unless required by applicable law or a lawful request from a competent governmental authority.
We will evaluate all vulnerability reports based on their content. However, we do not guarantee that every report will be publicly disclosed. Where appropriate, we will keep you informed of the progress of our handling of your report, including our assessment of the report and the expected timeline for resolution, if applicable.

Processing  Stage

Committed Timeline

Receive the vulnerability report and assignment of a tracking number

Within 7 working days.

Response with the initial validation result (valid / invalid / additional information required)

Within 10 working days.

Progress updates

At least once every 30 days until closure.

Release and public disclosure of the remediation measures

In principle, disclosure will be made within 90 days from the date the vulnerability is validated. The actual disclosure timeline may be adjusted based on the complexity of the remediation, the progress of supply chain coordination, the scope of impact, and the results of the risk assessment.

If your report is determined to be a valid vulnerability, we will acknowledge and credit you as the reporter in a security advisory, release notes, or other public communications, unless you request to remain anonymous in your email submission.
 
4. Legal Statement & Safe Harbor
For security research conducted in good faith and for the purpose of improving security in compliance with this Policy, ATP will not voluntarily pursue civil claims for damages against, or initiate criminal complaints against, a reporter, provided that all of the following conditions are satisfied. 
o The activities are conducted in good faith for the purpose of identifying or improving security vulnerabilities, comply with the requirements of this Policy, and do not involve malicious exploitation of vulnerabilities, unauthorized access, data theft, service disruption, or any other conduct that causes harm; and 
o The reporter does not publicly disclose any details of the vulnerability or any other information that may increase security risks before the vulnerability has been remediated or ATP has provided prior written consent for such disclosure. 
If a reporter fails to comply with this Policy, maliciously exploits a vulnerability, or engages in any unauthorized or unlawful conduct, ATP reserves the right to pursue civil remedies, initiate criminal complaints, and take any other legal actions available under applicable law.
This statement represents ATP's commitment solely with respect to the exercise of its own legal rights. It does not affect the lawful exercise of authority by any governmental authority, nor does it affect the rights of any third party to assert its legal rights.
 
5. Disclaimer
This policy and associated procedures may be updated without prior notice.
We are committed to addressing reported issues as quickly as reasonably practicable and will promptly release fixes or security updates once the issues have been resolved.

Security Update Download Link (if applicable)

 

Security Advisory

(if applicable)

 

Contact Us