Vulnerability Disclosure Policy
1. Purpose of this Policy
The Company considers ensuring the security safety of our products a vital mission. This policy aims to encourage vulnerability reporting and realize security improvements by building a cooperative relationship with reporters. The Company accepts vulnerability reports and strives to solve problems through constructive dialogue. In addition, we have established a PSIRT (Product Security Incident Response Team) to take responsible action from the reception of a vulnerability report to the completion of the response. This team works with related departments to take prompt and appropriate action. Furthermore, this policy is published in an easily accessible location on our website to ensure transparency.
2. Legal Protection
The Company respects good-faith vulnerability reporting activities and strives to provide legal protection within an appropriate scope. However, this does not comprehensively authorize all investigation activities against the Company’s systems, products, etc. Investigative activities by reporters shall be treated as authorized by the Company only within the permitted scope (targets, methods, conditions) stipulated in this policy. The Company will cooperate with reporters to resolve security issues caused by reported vulnerabilities. Furthermore, as a general rule, the Company will not take legal action regarding investigative activities conducted in good faith and sincerity by reporters in accordance with this policy. Note that if a third party takes legal action against such investigative activities, the Company will declare that the activities were authorized based on this policy, as long as the activities were conducted within the permitted scope stipulated in this policy.
3. Reporter Code of Conduct
If you discover a vulnerability regarding In-house products, or discover a leak of personal information, financial information, trade secrets, etc., please report it to the Company promptly. In addition, we ask reporters to provide the Company with a reasonable period of time to resolve the problem before disclosure.
4. Prohibited Testing Methods
The Company prohibits destructive or disruptive testing, such as the following:
Unauthorized access acts: Intrusion or authentication bypass into systems not explicitly permitted by the Company.
Denial of Service (DoS/DDoS): Mass access or overload attacks aimed at stopping the system.
Inappropriate handling of personal information: Disclosing personally identifiable information acquired during testing to a third party.
Other illegal acts: Acts involving copyright infringement, privacy infringement, out-of-scope operations, etc.
5. Scope of Application
This policy applies to products provided by the Company. Specifically, software embedded in our products is targeted. However, products and services provided by third parties, or systems explicitly excluded by the Company, are outside the scope of this policy. If the scope is unclear, please contact the Company before starting testing.
6. Reporting Method
Vulnerability reports are accepted via the Web form provided by the Company (https://watanabe.web-tools.biz/en-report-vulnerability). When reporting, please provide information such as the location of the vulnerability, its impact, and reproduction steps (including a Proof of Concept (PoC) code if possible). The Company provides an S/MIME public key and ensures secure communication means to protect the reporter’s privacy. Also, reporting can be done anonymously, and the reporter’s name and contact information will not be shared with a third party without explicit permission. The Company will acknowledge receipt as quickly as possible upon receiving a report, and conduct risk assessment and initial analysis. Investigation and correction may take time depending on the content, but we will share the progress and future response policy (including the correction plan, presence/absence of workarounds, and publication policy) with the reporter within a reasonable range.
7. Handling of Reported Vulnerability Information
Reported vulnerability information will only be used to fix and mitigate the vulnerability. The Company will strictly manage the vulnerability information so that it does not leak externally before publication and will protect the reporter’s privacy. Note that vulnerabilities affecting all users may be shared with relevant organizations (public institutions such as JPCERT/CC) as necessary.
8. Roles of Stakeholders
Stakeholders in this policy include the “Finder” who is an individual or organization discovering a vulnerability, the “Reporter” who notifies the Company of the vulnerability, the “Vendor” who creates and maintains the product with the vulnerability, and the “Coordinator” which is an external organization that facilitates the CVD process. The Company collaborates with these stakeholders to smoothly advance the vulnerability response process.
9. Vulnerability Response Process
After accepting a vulnerability report, the Company responds through a process of receipt acknowledgment, initial analysis, formulation of a correction plan and coordination with relevant external organizations, development of a correction program, and notification to the reporter. Once the correction is complete, we will guide you on countermeasures including updates using secure methods. Through this, we will minimize the impact of the vulnerability and ensure the safety of our customers and society as a whole.
10. Others
The contents of this policy are subject to change without notice. The Company shall not be liable beyond the scope permitted by law for any damages incurred by users, etc. as a result of the response based on this policy. Also, we do not pay bounties or rewards.