ISEKI & CO.,LTD.

Vulnerability Disclosure Policy

About This Policy

Vulnerability Handling Policy and Organization

ISEKI & CO., LTD. (“ISEKI”) is committed to protecting customers and users from cybersecurity risks associated with security vulnerabilities affecting our products. ISEKI has established a Product Security Incident Response Team (“ISEKI PSIRT”) as the focal point for vulnerability handling and product security incident response activities. ISEKI PSIRT coordinates and manages the receipt, assessment, investigation, remediation, regulatory reporting and disclosure of product security vulnerabilities.

ISEKI supports coordinated vulnerability disclosure in accordance with this Vulnerability Disclosure Policy (“Policy”). We seek to receive vulnerability reports safely and responsibly, investigate and remediate confirmed vulnerabilities in a timely manner, coordinate disclosure with relevant stakeholders where appropriate and necessary, and publish security advisories where necessary to help customers and users reduce cybersecurity risks.

Products Covered by this Policy

This Policy applies to products and diagnostic tools with digital elements developed by ISEKI and marketed under the ISEKI brand in the European market. This Policy also applies to products developed by ISEKI, even where certain components, software or development activities incorporated into those products are provided by external parties.

This Policy does not apply to products placed on the market under a third-party name, brand or trademark, even where ISEKI is involved in vulnerability handling, remediation, coordination or disclosure activities relating to such products. Please report vulnerabilities affecting such products through the contact point designated by the relevant brand owner.

Reports Outside the Scope of this Policy

The following reports are generally outside the scope of this Policy:

  • vulnerabilities that are already known to ISEKI;
  • reports based solely on automated scanning results or publicly available vulnerability information, without information indicating that an ISEKI product may be affected;
  • non-security bugs, general quality issues, repair requests or product support inquiries;
  • requests relating to sales, maintenance, parts, warranties or other general customer support matters.

General inquiries regarding ISEKI products and services should be made through the Contact page or your local distributor or dealer.

Reporting a Vulnerability

How to Report a Vulnerability

If you believe that you have identified a vulnerability in an ISEKI product within the scope of this Policy, please submit a report using the Vulnerability Reporting Form below.

Customers may also contact the dealer from whom they purchased the product to report a vulnerability.

Language

To facilitate efficient assessment and handling of vulnerability reports, ISEKI requests that reports, where possible, be submitted in English or Japanese. Please note that communications between ISEKI PSIRT and the reporter regarding vulnerability reports, investigation activities, remediation measures, coordinated disclosure and related matters will generally be conducted in English or Japanese.

Information to Include in a Vulnerability Report

To help ISEKI assess and respond to your report efficiently, please provide information such as:

  • contact information;
  • details of the affected product, software or firmware;
  • a description of the vulnerability, including any information supporting the belief that the product may be affected;
  • information that may help reproduce, verify or assess the issue;
  • information regarding the potential impact or severity;
  • proof-of-concept code, logs, screenshots or other supporting materials.

Please submit only information that is reasonably necessary for ISEKI to assess the reported vulnerability. Please do not include personal data, confidential information or any data belonging to ISEKI, customers or third parties unless such information is strictly necessary to demonstrate the vulnerability.

Secure Communication

Communication via the Vulnerability Reporting Form is encrypted and protected by SSL/TLS. If your report contains sensitive, non-public vulnerability information, proof-of-concept code, exploit details, logs, personal data or confidential information, please submit it through the Vulnerability Reporting Form. If you wish to provide additional files that cannot reasonably be submitted through the form, please indicate this in your report. ISEKI may provide instructions for secure file transfer.

How ISEKI Handles Reports

Confirmation of Receipt

After a vulnerability report has been submitted through the Vulnerability Reporting Form, ISEKI will send an acknowledgement of receipt usually within five business days, provided that sufficient contact information has been supplied. Please ensure that your email settings allow messages from our domain (@iseki.co.jp) to be received. Please note that confirmation of receipt may be delayed during company holidays, including the year-end and New Year period, late April to early May, and mid-August.

If a vulnerability report is submitted through a distributor or dealer, ISEKI may send its acknowledgement of receipt via that distributor or dealer. Please note that, as a result, additional time may be required before you receive the acknowledgement of receipt.

Validation and Investigation

After receiving a vulnerability report, ISEKI PSIRT will conduct a validation to determine whether the reported issue concerns a product within the scope of this Policy, and whether it appears to be reproducible. Where appropriate, ISEKI PSIRT will conduct or coordinate a detailed investigation of the reported issue. If ISEKI PSIRT determines that the reported issue does not affect a product within the scope of this Policy, is not reproducible, is outside the scope of this Policy, or does not provide sufficient information to support further investigation, ISEKI may close the report.

Assessment and Remediation

Based on the outcome of the investigation, ISEKI PSIRT will assess the severity, scope, exploitability and potential impact of the vulnerability. ISEKI PSIRT will determine whether remediation or mitigation measures are appropriate and, where necessary, coordinate their planning and implementation.

The availability and nature of remediation or mitigation measures will be determined based on factors such as the impact and severity of the vulnerability, technical feasibility, product lifecycle considerations, applicable legal requirements, and other relevant circumstances. The time required for investigation, remediation and disclosure may vary depending on the severity, exploitability, affected products, technical complexity, testing requirements, supply-chain impact and applicable legal or regulatory requirements.

Ongoing Communication

ISEKI values coordinated and good-faith communication with reporters. Where contact information has been provided, ISEKI will provide follow-up communication, as appropriate, regarding the handling and outcome of the report. ISEKI PSIRT may contact the reporter to request additional information where necessary.

Disclosure

Coordinated Vulnerability Disclosure

To minimize the impact on our customers and support the safe disclosure of information, ISEKI asks that reporters refrain from publicly disclosing or sharing information about unresolved vulnerabilities with third parties.

Nothing in this Policy is intended to restrict coordination with JPCERT/CC or other CERT/CSIRT organizations and competent authorities.

ISEKI may coordinate the timing and content of disclosure with the reporter, affected customers, dealers, distributors, suppliers, development partners, service partners, JPCERT/CC, CERT/CSIRT organizations, ENISA, competent authorities, industry organizations or other relevant stakeholders where appropriate.

Regulatory Reporting under Applicable Laws

Where required by applicable laws or regulations, including the EU Cyber Resilience Act, ISEKI may report actively exploited vulnerabilities, severe incidents affecting the security of products with digital elements, or other reportable cybersecurity matters to competent authorities, CSIRTs, ENISA or other relevant bodies. Such regulatory reporting may be conducted in parallel with, or separately from, coordinated vulnerability disclosure to customers, users, reporters and the public.

Nothing in this Policy limits ISEKI’s ability to take actions required by applicable laws, regulations, governmental authorities, courts or competent cybersecurity authorities.

Security Advisories

ISEKI determines whether, when and how information regarding product vulnerabilities will be disclosed by carefully assessing security risks, customer impact, remediation status, legal requirements and other relevant factors.

Where ISEKI determines that public disclosure is appropriate, information relating to confirmed product vulnerabilities will be published on the ISEKI website below:

ISEKI may also provide information through other appropriate channels, including direct communication to affected customers, dealers, distributors, service partners or other relevant stakeholders.

Researchers and Safe Harbor

Researcher Responsibilities

Researchers and reporters are expected to:

  • act in good faith and comply with all applicable laws and regulations;
  • conduct only the minimum testing necessary to identify and demonstrate the vulnerability;
  • avoid actions that may disrupt, damage, degrade or overload ISEKI products, services, networks, systems, customers, users, dealers, suppliers or third parties;
  • avoid accessing, acquiring, modifying, deleting, storing or disclosing personal data or confidential information beyond what is strictly necessary to demonstrate the vulnerability;
  • protect any information obtained during security research from unauthorized access, use or disclosure;
  • promptly delete any unnecessary data obtained during research;
  • submit vulnerability reports through the designated reporting channels;
  • provide reasonable cooperation to ISEKI during investigation and coordinated disclosure;
  • refrain from public disclosure or sharing information about the vulnerability with third parties until ISEKI has confirmed that the vulnerability has been resolved.

Legal Safe Harbor for Good-Faith Reports

If the following conditions are met, ISEKI does not intend to initiate legal action against you or seek to hold you liable for your actions:

  • you act in good faith and comply with this Policy;
  • you did not intend to cause harm to ISEKI, our customers, users, dealers, suppliers or any third party;
  • you do not disrupt, damage, degrade or overload ISEKI services, systems, networks or business operations, or ISEKI products belonging to or used by ISEKI, our customers, users, dealers, suppliers or other third parties;
  • you do not infringe upon the privacy or security of our customers, users or third parties;
  • you do not access, acquire, modify, delete, store or disclose personal data or confidential information beyond what is strictly necessary to demonstrate the vulnerability;
  • you do not use the vulnerability or related information for extortion, threats, coercion or financial demands;
  • you comply with all applicable laws and regulations;
  • you do not publicly disclose or share information about the vulnerability with third parties until it has been confirmed by ISEKI as resolved, unless otherwise required by applicable law.

This safe harbor does not apply to activities involving unauthorized access, data exfiltration, data modification, service disruption, extortion, threats, privacy violations, intellectual property infringement, physical attacks, social engineering or any other unlawful conduct.

Recognition and Administrative Information

Acknowledgements

ISEKI may acknowledge individuals or organizations who have contributed to the discovery or resolution of vulnerabilities in our products by including an acknowledgement in the relevant security advisory, subject to the contributor’s consent. If multiple reports are received for the same vulnerability, acknowledgement will generally be given to the first individual or organization to report the vulnerability, subject to ISEKI’s reasonable determination.

ISEKI may decline acknowledgement where doing so would be inappropriate, unlawful, misleading, inconsistent with coordinated disclosure, or otherwise unsuitable.

No Bug Bounty

This Policy is not a bug bounty program. ISEKI does not offer financial remuneration, rewards, gifts or other compensation for the submission of vulnerability information unless otherwise expressly stated in a separate written program.

Privacy and Personal Data

Personal data provided in connection with vulnerability reports will be handled appropriately in accordance with our Privacy Policy and will be used for purposes such as receiving, assessing, investigating, responding to, remediating, disclosing, documenting and complying with legal obligations relating to vulnerability reports. Such data will not be disclosed to third parties or used for unrelated purposes, except where disclosure is necessary for vulnerability handling, coordinated disclosure, supplier coordination, regulatory reporting, legal compliance, protection of rights, or other legitimate and lawful purposes.

Before submitting a vulnerability report, please read our Privacy Policy.

Revision of this Policy

ISEKI may revise this Policy from time to time to reflect changes in applicable laws and regulations, standards, vulnerability disclosure practices, vulnerability handling processes or ISEKI’s internal processes.