Support
Security
Security Policy
TAKEBISHI CORPORATION has obtained ISO 27001 (ISMS) certification − a leading international standard for information security management systems − as the company believes it is important to manage and utilize its information assets safely and appropriately in a way that meets the trust that the customers and society put in the company along with their requirements.
Please see below for details.
Information Security Management Systems | TAKEBISHI CORPORATION
Vulnerability Disclosure Policy
Overview
We place great importance on the security of products that we develop and manufacture, and we welcome vulnerability reports from external parties. This page explains how to report vulnerabilities, our response policy, and how we handle reporters.
Scope
- Vulnerabilities in software, firmware, and embedded devices that we develop and manufacture
- Security misconfigurations and signs of unauthorized access
- Out of scope: services managed by third parties and end-of-support products
How to Report
Please report vulnerability information through the vulnerability report form.
Open the vulnerability report form
- After confirming receipt of vulnerability information, we will contact you within 2 business days to acknowledge receipt.
Please note that reports submitted on Saturdays, Sundays, public holidays, company holidays, or outside business hours will be received on the next business day or later.
- Communication with reporters after submission through the vulnerability reporting contact (vulnerability report form) will be handled by email.
- We will keep the reporter informed of the progress of our investigation and response by email — when the status changes and upon inquiry — until the issue is resolved.
We handle vulnerabilities with reference to ISO/IEC 29147 and the Information Security Early Warning Partnership Guidelines (published by IPA, Information-technology Promotion Agency, Japan).
Investigation and Countermeasures
We will determine whether the reported issue is a "new vulnerability" based on the following criteria.
- It affects product security
- It is reproducible
- It has not been publicly disclosed
If necessary, we may request additional information to support our review.
If the issue is confirmed to be a new vulnerability, we will implement countermeasures and prepare for public disclosure.
If the issue is not confirmed to be a new vulnerability, we will explain the result to the reporter and close the case.
Publication of Vulnerability Information
We publish a security advisory on our website for vulnerabilities for which a remedy (such as a security update) has been made available. This includes vulnerabilities originating in third-party software (such as OSS) bundled with our products.
- Content: description of the vulnerability, identifiers such as CVE IDs, affected products and versions, severity (CVSS), and the fixed version or workaround
- Timing: in principle, after the remedy has been made available. The timing is determined in consultation with the reporter, coordinating organizations (such as JPCERT/CC), and other relevant parties, based on the principles of Coordinated Vulnerability Disclosure (CVD)
- Exceptions: for vulnerabilities that are being actively exploited, we may notify affected customers or publish interim workarounds before a remedy becomes available
- Updates: if the published content changes, we revise the advisory with the date of the update
- Vulnerabilities confirmed to have no impact on our products (for example, those in unused features of bundled software) may not be published
Security advisories are published on our website at the link below.
Open Security Advisories
Acknowledgements
With the reporter's consent, we credit the reporter by name (or handle) in the security advisory. If the same vulnerability is reported by multiple parties, the first reporter is credited. We will not publish a reporter's name without consent, except as required by law.
Safe Harbor
We will not take legal action (civil claims or criminal complaints) against reporters for vulnerability research and reporting conducted in good faith and in accordance with this policy.
This provision applies to research and reporting that meets all of the following conditions:
- The report is within the scope of this policy and is submitted through the reporting channel described above
- The research does not involve obtaining, altering, or deleting data, or disrupting or degrading services, beyond the minimum necessary to confirm the vulnerability
- If personal or confidential information is accessed in the course of the research, the reporter immediately stops the research, notifies us, and does not retain or disclose that information
- The vulnerability information is not disclosed to any third party until we publish it or until a date agreed upon with us
- No money or other benefit is demanded in return for the report
Please note that this provision describes our own policy regarding legal action and does not bind third parties or law-enforcement authorities. If you are unsure whether your research complies with this policy, please contact us in advance through the reporting channel.
Disclaimer
This policy may be updated without prior notice. Please refer to this page for the latest version.
Vulnerability Report Form
Open the vulnerability report form

