- Introduction
Noritsu Precision Co., Ltd. (hereinafter referred to as “the Company”) is committed to continuously maintaining and improving the security of its products in order to provide customers with highly secure products and services. This policy sets forth the basic principles regarding the disclosure of information when vulnerabilities are discovered in the Company’s products and services. - Purpose of Disclosure
- To minimize customer damage by promptly providing accurate information to customers and encouraging appropriate countermeasures.
- To maintain and improve the reliability of products and services through highly transparent information disclosure.
- Basic Principles of Disclosure
The Company will act based on the following principles when disclosing vulnerability information:- We will contact you to confirm receipt within 5 business days of receiving the report.
- We will respect the principle of Coordinated Vulnerability Disclosure (CVD).
- We will coordinate the public disclosure of vulnerability information in cooperation with the vulnerability discoverer, and the Company until countermeasures are ready.
- In principle, information will be disclosed when countermeasures (corrective patches, workarounds, etc.) are established and available to customers. We provide accurate and easy-to-understand information to avoid misunderstandings and confusion among our customers.
- Information Disclosure Content and Timing
- 4.1. Information to be Disclosed Disclosed information will include at least the following:
- Vulnerability overview and severity (CVSS score, etc.).
- Affected product/service name and versions.
- Measures that customers should take (application of patches, workarounds, etc.).
- Relevant CVE ID (if available).
- 4.2. Adjustment of Disclosure Timing
- The preparation period for information disclosure varies depending on the severity of the vulnerability, the scope of impact, and the difficulty of countermeasures.
- As a general rule, we will disclose information once we have completed countermeasures for the vulnerability and customers can apply those countermeasures.
- In cases deemed highly urgent, such as zero-day attacks, we may disclose provisional information (workarounds, etc.) even if countermeasures are not yet complete, in order to prevent further damage to customers.
- 4.1. Information to be Disclosed Disclosed information will include at least the following:
- Support Period
The support period for vulnerabilities in our products is 5 years from the product release, or the shorter of the product lifecycle. - Information Disclosure Channels
Information regarding vulnerabilities in our products and services will be disclosed through the following channels:- Our website’s security information page (PSIRT-related pages)
- Information disclosure in cooperation with coordinating organizations such as JPCERT/CC
- Other
This policy may be changed without notice as needed.
Please always check this security information page for the latest information.
If you discover any security vulnerabilities in our products, please report them using the “Vulnerability Report Form” as a general rule, in order to ensure a prompt and thorough investigation.
For inquiries regarding vulnerability reports, please contact the following:
Department: Service Promotion Office
E-mail: cra_tsd@noritsu.com



