Guided by its core values of Environmental, Social, and Governance (ESG), Sercomm advances sustainable development through a multi-dimensional approach, translating commitments into concrete actions while actively aligning with international sustainability standards and supporting the United Nations Sustainable Development Goals (SDGs). Since 2017, the Company has published an annual Sustainability Report, and by 2024 had issued reports for nine consecutive years, all of which have continued to receive independent third-party international assurance, demonstrating Sercomm’s sustained efforts and achievements in sustainability governance.
In 2024, Sercomm was awarded the EcoVadis Gold Medal and ranked within the top 6%–20% in the 11th Corporate Governance Evaluation conducted by the Taiwan Stock Exchange. Sercomm’s U.S. subsidiary received the Great Place To Work® certification, while the Suzhou subsidiary was recognized as a 2024–2025 Forbes China Sustainable Innovation and Development Enterprise. In addition, the Chunan Manufacturing Center achieved RBA VAP Platinum certification, further affirming the Company’s accomplishments in corporate governance, workplace practices, and sustainable supply chain management.
To effectively address stakeholder expectations and ensure consistent progress on sustainability issues across Environmental, Social, and Governance (ESG) dimensions, Sercomm’s sustainability strategy is continuously refined. It aligns with the core principles of the United Nations Sustainable Development Goals (SDGs), Sercomm’s identified sustainability risks and opportunities, and annual materiality assessment results. These elements are integrated into a unified sustainability framework that guides action plans and the formulation of short-, medium-, and long-term goals.
In the areas of labor rights, environmental protection, and ethical business conduct, Sercomm actively follows the Code of Conduct of the Responsible Business Alliance (RBA). The Company conducts self-assessments across key dimensions, including Labor, Health & Safety, Environmental protection, Ethics, and Management Systems, and proactively pursues relevant certifications to strengthen responsible business practices.
Manufacturing centers in China, Taiwan, and the Philippines continue to comply with RBA requirements and regularly undergo third-party audits and assessments to ensure the effective implementation of management systems related to labor, human rights, environmental protection, and business ethics. Details of audit results are disclosed in Sercomm’s annual Sustainability Reports.
Sercomm upholds a procurement policy grounded in “Respect for Human Rights,” “Environmental Friendliness,” “Integrity,” and “Mutual Benefit.” In addition to demanding excellence in quality, cost, delivery, environmental health and safety, and human rights from its suppliers, Sercomm explicitly emphasizes its commitment to a responsible supply chain. The Company has gradually established a pragmatic sustainable supply chain management process, requiring suppliers to comply with the Responsible Business Alliance (RBA) standards on human rights, environmental protection, and business ethics, as well as green product regulations such as RoHS and REACH.
Furthermore, Sercomm communicates key policies to its supply chain partners, including carbon reduction and energy conservation, responsible minerals sourcing, local procurement, and green purchasing. Through mutual sharing, audits, and support programs, the Company works hand-in-hand with its suppliers to achieve sustainable development and foster win-win cooperation.
To effectively manage business and sustainability-related risks within the supply chain, Sercomm has established the Supplier Management Procedure, which defines the internal mechanisms for managing both new and existing suppliers and provides supporting resources. In line with the Responsible Business Alliance (RBA) standards, we require all affiliated suppliers to adhere to principles of corporate social responsibility and business integrity, as well as to fully comply with all applicable local laws and regulations.
To reinforce these expectations, we have instituted the Supplier’s Code of Conduct Agreement, which must be signed by suppliers to be considered qualified vendors. Furthermore, we have strengthened our existing management systems by tailoring supplier selection and evaluation mechanisms based on supplier characteristics.
Sercomm has established the Information Security Committee, which is responsible for the oversight and governance of the company’s information security. The committee is chaired by the Chief Operating Officer (COO) and convenes regularly to review and approve information security strategies and policies, ensuring the effectiveness of information security measures. The committee also reports annually to the Board of Directors on information security performance, related issues, and strategic directions.
Under the committee, an Information Security Task Force has been formed, consisting of representatives from various departments across domestic and overseas subsidiaries. This task force coordinates the formulation, implementation, risk management, and compliance auditing of information security and protection policies, following the PDCA (Plan-Do-Check-Act) management cycle. The task force also submits annual reports on the progress and results of its information security initiatives to the committee.
To enforce effective information security management and ensure the security of critical infrastructure, application systems, products, and customer information, Sercomm has implemented the Information Security Policy as a guiding framework. This policy is reviewed and approved by the chairperson of the Information Security Committee and officially enacted.
Product Information Security
Sercomm Product Security Incident Reponse Team (PSIRT) receives, handles, and discloses security vulnerabilities related to Sercomm's products and solutions, and is the only channel to disclose vulnerabilities. Sercomm encourages researches, industry organizations, and providers to report security vulnerabilities related to our products to Sercomm PSIRT. Please include but not limited to the following information in your email for verifying a vulnerability:
- Affected products and versions (including product names, types, version numbers, origins, and locations)
- Detailed description (technical details such as system configurations, proof of concent, how the vulnerability was found, specific tools or techniques used, and impacts of exploiting the vulnerability)
- Exploitation (whether the vulnerability) has been explited, and whether the explitation is publicly available)
- Contact information of the reporter
Please contact us by sending an email to PSIRT@sercomm.com
- Get a hold of the information on threats to information security and its protection technology
- Breach of information security and how it was handled
- Educational training and promotion on cases of information security
- Periodic evaluation for information contractors
- Corporate information security risk evaluation
- Information security risk evaluation and formulate incident management procedures
- Compliance with international standards (ISO/IEC 27001)
- Defining confidential and sensitive information and data encryption
- Ongoing monitoring of information security
- Period scan of vulnerabilities
- Simulation on penetration tests of systems
- Check on confidential information and risk evaluation
- Disaster recovery simulation
- Receive international certification for information security
- Physical and environmental safety
- Labor resources security
- Network communications security
- Access control and management
- Information security incidents management
- Ongoing management of the operation with respect to information security
- Data security
- Management on supplier security
- Identification of information security regulations
The supervisor or designated personnel of each risk management unit shall be responsible for the second line responsibility management of related businesses, clearly grasps the effective implementation of various risk regulations, allocates limited resources efficiently to related risk management work, proposes countermeasures and recovery plans when risk incidents are discovered, and consults external experts as needed, and implements additional relevant internal regulations after reporting to the operation and management committee for resolution.
Sercomm has compiled a stakeholder list based on the industry context and characteristics, and identified key stakeholders in reference to the five core principles outlined in the AA1000 Stakeholder Engagement Standard 2015 (AA1000 SES) published by AccountAbility. The identified key stakeholders include seven categories: customers, ESG rating and evaluation organizations, employees, suppliers, government agencies, investors/financial institutions, and media.
To proactively understand the needs and concerns of stakeholders, Sercomm has assigned dedicated responsible units for timely communication, response, review, and improvement. Following the publication of each year’s sustainability report, the Company reports its stakeholder communication status to the Board of Directors at least once annually.
In alignment with the European Union's Double Materiality principle, stakeholder feedback is incorporated into the materiality assessment process. Furthermore, Sercomm has deepened the analysis of both positive and negative impacts, enabling stakeholders and information users to better understand the Company’s significant internal and external impacts throughout its economic activities.
Details of the material topics for 2024 are provided in the Sustainability Report.
Sercomm has established the “Employee Code of Conduct” and “Procedures for Handling Internal Material Information” as the guides for employees to execute the business activities. The Code consists of the general provisions, relationship with customers and suppliers, and conflict of interest. The general provisions cover Sercomm’s corporate ethical management policy. Sercomm organizes the orientation training, general education training and management development training periodically in order to propagate the corporate ethical management policy.
Sercomm is committed to enhance the timeliness and transparency of information disclosure. It discloses its financial and business information on MOPS, and also holds the investors’ meeting semi-annually. Sercomm attends the investors’ forum and investors’ meeting organized by domestic/overseas securities firms from time to time in order to present the financial figures and business performance already disclosed and to strengthen investors’ knowledge about the Company’s financial business information