Basic Policy

YASDA has established an in-house PSIRT (*1) and strives to improve product security while promoting measures to address vulnerabilities (*2). This Vulnerability Disclosure Policy (hereinafter referred to as this Policy) sets forth the handling of information concerning any vulnerability identified in our products.
Our basic policy is to accept vulnerability reports in good faith, appropriately manage information concerning reporters and undisclosed vulnerabilities, conduct investigations, provide progress updates, implement remediation, and engage in coordinated disclosure in consultation with relevant parties.

*1)PSIRT: An organization responsible for implementing security measures for products and services. Product Security Incident Response Team.
*2)Vulnerability: A cybersecurity weakness or flaw that may adversely affect the confidentiality, integrity, or availability of a product.

Vulnerability Response

If a vulnerability in one of our products is discovered or reported, we will respond in accordance with the following steps.

1.Report Intake

      If you discover a vulnerability in one of our products, please contact us.
      For information on how to contact us, please refer to “Vulnerability Reporting Contact” below.
      Normally, we will notify the reporter within 5 business days that we have received the vulnerability report.
      We may ask the reporter to provide additional information.

2.Vulnerability Investigation

      Based on the vulnerability information provided, we will conduct the necessary investigations,
      including confirming reproducibility, identifying affected products, and assessing the level of security risk.
      To the extent that the information can be shared, we will inform the reporter of the investigation results
      and our planned course of action.

3.Vulnerability Response

      Based on the assessed risk level, we will implement measures to address the vulnerability,
      such as providing a security patch or a fixed version of the software.
      If fundamental remediation, such as an update, cannot be implemented immediately,
      we will provide corrective actions such as configuration changes, temporary workarounds, or mitigations.

4.Information Disclosure

      Once remediation, temporary workarounds, mitigations,
      or other measures for the vulnerability are complete and the information is ready for release,
      we will disclose information concerning the vulnerability. Taking into account which products and customers are affected,
      the potential for exploitation, the risks associated with disclosure, and other circumstances,
      we will provide the information by publishing it on our website, directly notifying affected customers, or both.
      As necessary, we will coordinate the timing of information disclosure with the reporter and
      other relevant parties, including related vendors and suppliers.

Vulnerability Reporting Contact

If you discover a vulnerability in one of our products, please contact our inquiry desk for Product Security. If you use the email inquiry form, select “Product Security” as the inquiry type.

When contacting us, providing the following information will help us process your report smoothly. – Model and serial number

  – Reporter’s name, affiliation, and contact details
  – Details of the vulnerability (please provide as much information as you can)
   ✔Details of the event or issue identified (what kind of vulnerability it is)
   ✔Conditions under which it occurs (the machine’s operating environment, network configuration, functions in use, etc.)
   ✔Actual or anticipated impact
   ✔Steps to reproduce the event or issue, if reproducible

*The vulnerability information and information concerning the reporter that you provide will be managed in accordance with this Policy and our Privacy Policy.

*When contacting us, for security reasons, do not include confidential information such as “highly sensitive steps for reproducing the vulnerability,” “logs,” or “weaponized proof-of-concept code.”

*Although we do not offer a bounty program, after remediation of the vulnerability is complete, we will, upon request, acknowledge the reporter in the advisory we publish.

Scope

This Policy applies to products provided by the Company (hardware, software, firmware, and third-party components integrated by the Company). However, incidents such as those listed below are outside the scope of response under this Policy.

– Vulnerabilities caused by customer modifications to our products, use outside the scope intended by the Company, or similar factors
– Vulnerabilities resulting from social engineering

Changes to This Policy

The content of this Policy is subject to change, so please check it periodically. Unless otherwise specified by the Company, the revised Policy will take effect when it is posted on this Site.

September 01, 2026

YASDA PRECISION TOOLS K.K.

TOP