PlatformsFaststream SiliconFaststream RadioFaststream VisionConnected EdgeFaststream SecureMobility & Rail
ProductsSemiconductor IPWireless & RANEdge & GatewaysTracking & IdentificationSoftware & FrameworksConnected Systems
TechnologyRTL to GDSIIVerification methodologyDFT and silicon testLow-power designMixed-signal integrationDesign enablement5G protocol stackWireless and RF architectureBaseband and low PHYForward error correctionControl and data planeHigh-speed interfacesFirmware and bootSilicon root of trustSoftware-defined vehicleAutomotive OTAFunctional safety
AIAI Engineering ServicesEdge AI & Embedded MLComputer Vision EngineeringSensor Fusion & PerceptionAI Silicon & AccelerationMLOps for DevicesAI Visual InspectionPredictive MaintenanceDriver MonitoringVideo Analytics & Safety
SolutionsSemiconductorIndustrial AIConnected ProductsAsset TrackingAutomotive & MobilitySmart InfrastructureSecure IdentityWireless & SatelliteSmart WashroomsFuel ManagementSmart BuildingsWorker SafetyEnergy MonitoringSmart AgricultureSmart CityAutonomous PlatformsAssembly AutomationLiDAR Rail SafetyHardware Wallet
IndustriesSemiconductorTelecommunicationsIndustrial & ManufacturingAutomotive & MobilityTransportation & RailAerospace & DefenceHealthcare & MedicalEnergy & UtilitiesOil & GasRetailConsumer ElectronicsMedia & EntertainmentSmart Infrastructure & IoT
ServicesSystem Integration overviewASIC & SoC DesignFPGA DesignFPGA-to-ASIC ConversionAnalog, Mixed-Signal & RFHardware & High-Speed PCBEmbedded SoftwareCloud, OTA & Device ManagementManufacturing TransitionHow we engage
InsightCase StudiesKnowledge CenterWhite PapersGlossaryNewsletterResources & Support
CompanyAbout FaststreamEngineering ExcellenceLeadership & OrganisationHow We EngageQuality & ComplianceStandards & EcosystemPartners & EcosystemTrust CentreLocations & DeliveryNewsroom & MediaCareers
ContactStart a projectHow we engage
Talk to an engineer
COMPANY

Trust Centre

How to report a vulnerability, how Faststream handles one, and what security commitments apply to engagements. A supplier without a disclosure process does not have fewer vulnerabilities; it has fewer that anyone has told them about.

VULNERABILITY DISCLOSURE

How to report, and what happens next.

01

Report it

Email info@faststreamtech.com with the subject line beginning SECURITY. Include what you found, how to reproduce it, and what you assess the impact to be. A machine-readable contact is published at /.well-known/security.txt.

02

Acknowledgement

Within three working days, from a person rather than an autoresponder.

03

Assessment

Reproduction, impact assessment and identification of which products, versions or engagements are affected. We will tell you what we conclude, including if we conclude it is not a vulnerability and why.

04

Remediation

A fix developed and, where a customer product is affected, coordinated with that customer so a patch and an advisory arrive together.

05

Disclosure

Coordinated. We will agree a timeline with you rather than impose one, and we will not threaten a researcher who reports in good faith.

06

Credit

Acknowledged by name if you want it, and not if you do not.

COMMITMENTS

What we will not do to a reporter.

ENGAGEMENT SECURITY

How customer material is handled.

Security practice in engagements
AreaPractice
ConfidentialityCustomer designs, data and identities are not disclosed. Case studies are published at property level with names omitted unless disclosure is explicitly approved
Access controlProgramme material accessible to the assigned team, not to the organisation generally
Data locationEstablished at scoping where residency or export control requires it, and honoured by design rather than by policy
Development environmentSegregated per customer where the engagement requires it
Third-party IPLicence terms honoured; provenance of anything integrated into a customer design recorded
DepartureAccess revoked on team change; material returned or destroyed on request at engagement end
SubprocessorsNamed, and used only where the customer agreement permits
WHAT WE DO NOT CLAIM

An honest position on security posture.

Faststream does not describe any system it builds as impossible to attack. A tamper-evident design is described as tamper-evident. Assurance is a matter of degree, and the degree appropriate to an application is established during engagement rather than asserted on a website.

Nor does this page claim a certification Faststream does not hold. Which security certifications and attestations apply is confirmed at enquiry, for the same reason as everywhere else: a stale claim is worse than no claim.

COMMON QUESTIONS

What engineers ask before they call.

01

How do I report a security vulnerability to Faststream Technologies?

Email info@faststreamtech.com with a subject line beginning SECURITY, describing what you found, how to reproduce it and the impact you assess. A machine-readable contact is published at /.well-known/security.txt. Acknowledgement comes within three working days.

02

Will Faststream take legal action against a researcher?

No, where the report is made in good faith, avoids privacy violations and data destruction, and allows reasonable time to respond. We also do not require an NDA as a condition of receiving a report.

03

How is customer design material protected?

Access is limited to the assigned team rather than the organisation, environments are segregated per customer where the engagement requires it, data location is established at scoping, and material is returned or destroyed on request at engagement end.

KEEP READING

Related work.

BUILD WITH FASTSTREAM

Bring us the difficult part.

Tell us the specification, the constraint and the deadline. Programmes that cross silicon, radio, embedded and AI are where Faststream is strongest.