Kyoritsu Electrical Instruments Works, Ltd. (hereinafter called "We") accepts reports from our customers to improve the security of our products.

What Is a Vulnerability?

Vulnerability refers to a weakness or defect that could be exploited by a third party.

Gathering vulnerability reports

We will receive vulnerability reports related to our products from customers and external parties.
If you discover a potential vulnerability, please contact us in accordance with the procedures described below.

Scope

Contact for vulnerability reports accepts vulnerability reports concerning the following products and services provided by our company.

  • Products (including firmware)
  • Software, Application, and Driver (including downloadable version)

Report procedures

If you discover a potential vulnerability, please send a report to Contact for vulnerability reports by using Vulnerability Report Form.
In that case, please include the following information.

Necessary information
  • Product model number and serial number related to the vulnerability
  • Application name and OS version
  • Details of the vulnerability
  • Steps to reproduce the vulnerability, and
  • Name, phone number, and e-mail address of the reporter
Contact for vulnerability reports

* Contact for vulnerability reports is to be used only to report vulnerabilities. 
* Personal information will be handled securely in accordance with our Privacy Policy.
* We will send an acknowledgment of receipt to the reporter within five working days of receiving the report. Please note that our response may be delayed during the year-end and New Year holiday, summer holiday, and Golden Week period.

How to handle vulnerabilities

If a reported vulnerability is found to affect our products, we will assess the impact and determine appropriate actions and countermeasures based on the results of our investigation.
Regarding the reporting and disclosure of vulnerability information, we will consult with the relevant authorities and take appropriate actions as necessary.
*Please note that, depending on the circumstances, we may not be able to take actions on vulnerability reports provided.