Company Background and Ownership
TP-Link Systems Security Facts and Commitment
-
Security at TP-Link Systems is a core pillar of the company’s product strategy and corporate ethos. TP-Link stands for rigorous product security and user privacy protections. Since our founding we have developed and refined a comprehensive security framework designed to anticipate, identify, and address risks swiftly and transparently.
-
TP-Link Systems has signed the U.S. Cybersecurity and Infrastructure Security Agency’s “Secure by Design” pledge on secure product development and is a participating member in CISA’s Secure by Design Technical Exchange Group.
-
TP-Link Systems is an active participant in global security initiatives and has a proactive vulnerability disclosure program. Independent researchers and the security community can report potential issues to security@tp-link.com.
-
TP-Link Systems is preparing, in Q1 2025, to sponsor a bug bounty program hosted by a prominent bug bounty platform.
-
TP-Link Systems acknowledges that vulnerabilities exist across the industry. However, contrary to claims of widespread vulnerabilities, comparative data places TP-Link Systems on par with or ahead of other major industry players in terms of security outcomes.
-
Finite State, an independent U.S. cybersecurity company, is assisting TP-Link Systems to review and validate our security investments.
-
Finite State’s findings are unambiguous: TP-Link Systems is on par with or ahead of other major industry players in terms of security outcomes. Public vulnerability data (sourced from recognized security repositories like CVE Details and VulDB) show that TP-Link Systems' rate of vulnerabilities per product is significantly lower than those of peer manufacturers. The company's average CVSS score—an industry-standard metric for vulnerability severity—is in line with other leading manufacturers.
-
TP-Link Systems strives to be a leader in IoT and networking security, while acknowledging that security is never final and always evolving. By working with industry experts, embracing government guidance and standards, and maintaining an unwavering focus on improvement, we ensure that our customers can trust our devices, today and in the future.
TP-Link Systems is continuously engaging in events such the Zero Day Initiative’s PWN2OWN competition, demonstrating our openness to being tested by the world’s best security minds and our willingness to rapidly address and remediate discovered issues. -
TP-Link Systems supports efforts to increase product security and user data protections across the networking and connected device ecosystems. TP-Link Systems has applied to become a stakeholder for the Cyber Trust Mark program administered by UL Solutions and intends to seek and obtain Cyber Trust Mark certifications for its products. The company also intends to meet any standards required in the future for its products to be eligible for use in federal procurement and related supply chains.