NISSEI ASB MACHINE CO., LTD. and its affiliated companies (hereinafter "ASB Group" or “We”) is committed to ensuring the security of its products and services and protecting customers from cyber threats.
To this end, we collect and disclose information regarding product vulnerabilities.
We have established a Product Security Incident Response Team (PSIRT) to address vulnerabilities related to its products.
The PSIRT collects information on product security vulnerabilities from various sources and identifies and mitigates risks based on this information.
This policy applies to products manufactured or marketed (e.g. Auxilliary Equipment, spare parts) by us and applications provided by us that are used in conjunction with those products (hereinafter referred to as "Applicable Products").
The following types of vulnerabilities are excluded from reporting:
Regardless of the content of the vulnerability information (hereinafter referred to as "Vulnerability Information"), we do not offer any rewards (monetary or otherwise) to individuals or entities who report vulnerabilities (hereinafter referred to as "Reporters").
The reporting form is for vulnerability submissions only.
We check the report and send an acknowledgment email to the specified email address without delay.
Upon receiving a report, we will review the content.Please note that we may utilize Artificial Intelligence (AI) tools to assist in the initial triage and technical analysis of the report. However, all final evaluations and decisions will be made by human personnel. If the reported issue is determined to be a new vulnerability, we will promptly notify the Reporter via the specified email address.
Progress updates will be provided as necessary. If the issue is confirmed as a new vulnerability, we will coordinate with relevant parties* to determine the disclosure date and publish a security advisory once preparations are complete.
Additional information may be requested during the investigation process, and cooperation is appreciated.
*Relevant parties may include:
In responding to vulnerabilities and security incidents, we may collaborate with government agencies as necessary to provide information to customers.
Vulnerability information and countermeasures will be disclosed at an appropriate time.
If a vulnerability is deemed to potentially affect specific customers, we may contact them individually.
By submitting Vulnerability Information to us, the Reporter agrees to the following:
Personal information will be handled in accordance with our Privacy Policy outlined below.
If you have identified a potential security vulnerability in a product supported by Corporate Group, please report it to the email address provided at the bottom of this section. Before sending your report, please carefully read the following important notices and required information.
When reporting, please be sure to include the following information in your email.Please note that inquiries with missing required information will not receive a response.
To ensure accurate investigation and resolution, please also include as much of the following information as possible: