Security Vulnerability Disclosure Policy

NISSEI ASB MACHINE CO., LTD. and its affiliated companies (hereinafter "ASB Group" or “We”) is committed to ensuring the security of its products and services and protecting customers from cyber threats.
To this end, we collect and disclose information regarding product vulnerabilities.

1. Product Vulnerability Management

We have established a Product Security Incident Response Team (PSIRT) to address vulnerabilities related to its products.
The PSIRT collects information on product security vulnerabilities from various sources and identifies and mitigates risks based on this information.

2. Applicable Products

This policy applies to products manufactured or marketed (e.g. Auxilliary Equipment, spare parts) by us and applications provided by us that are used in conjunction with those products (hereinafter referred to as "Applicable Products").

3. Exclusions

The following types of vulnerabilities are excluded from reporting:

4. Bug Bounty Program

Regardless of the content of the vulnerability information (hereinafter referred to as "Vulnerability Information"), we do not offer any rewards (monetary or otherwise) to individuals or entities who report vulnerabilities (hereinafter referred to as "Reporters").

5. Handling of Vulnerability Information

5.1. Submission

The reporting form is for vulnerability submissions only.
We check the report and send an acknowledgment email to the specified email address without delay.

5.2. Initial Response

Upon receiving a report, we will review the content.Please note that we may utilize Artificial Intelligence (AI) tools to assist in the initial triage and technical analysis of the report. However, all final evaluations and decisions will be made by human personnel. If the reported issue is determined to be a new vulnerability, we will promptly notify the Reporter via the specified email address.

5.3. Investigation, Response, and Disclosure

Progress updates will be provided as necessary. If the issue is confirmed as a new vulnerability, we will coordinate with relevant parties* to determine the disclosure date and publish a security advisory once preparations are complete.
Additional information may be requested during the investigation process, and cooperation is appreciated.
*Relevant parties may include:

6. Vulnerability Countermeasures

In responding to vulnerabilities and security incidents, we may collaborate with government agencies as necessary to provide information to customers.
Vulnerability information and countermeasures will be disclosed at an appropriate time.
If a vulnerability is deemed to potentially affect specific customers, we may contact them individually.

7. Rights Regarding Reported Vulnerability Information

By submitting Vulnerability Information to us, the Reporter agrees to the following:

8. Handling of Personal Information and Contact Information

Personal information will be handled in accordance with our Privacy Policy outlined below.

Contact Information for Vulnerability Reporting

If you have identified a potential security vulnerability in a product supported by Corporate Group, please report it to the email address provided at the bottom of this section. Before sending your report, please carefully read the following important notices and required information.

Required Information

When reporting, please be sure to include the following information in your email.Please note that inquiries with missing required information will not receive a response.

Detailed Information

To ensure accurate investigation and resolution, please also include as much of the following information as possible:

Contact Email

Click reCAPTCHA to reveal E-Mail

Following submission, subsequent communication will take place via email.