1. Product Security Basic Policy
To provide customers with secure and highly reliable products and services, Kikusui Electronics Corporation (“Kikusui”) positions product security as one of its core quality elements and continuously ensures security and manages vulnerabilities throughout the entire product life cycle.
- Product Security Promotion Framework
To promote product security activities throughout the company, the Kikusui Group companies work together to continuously strengthen the organizational framework through efforts such as vulnerability management for products and services, enhanced governance, and improved employee education. - Provision of Products and Services with Security Considerations*1
Throughout the entire product lifecycle, from planning, development, evaluation, and shipment to operation, maintenance, and disposal, we establish design and operational processes that take cyberattack mitigation into account and promote the provision of secure products. - Response to Vulnerabilities and Incidents
We broadly collect and monitor vulnerability information related to products and services and promptly take measures to address identified vulnerabilities. In the event of a security incident, we also make necessary reports and disclosures under a prompt response framework and strive to identify the cause and prevent recurrence. - Provision of Security Information on Products and Services
For vulnerability information provided by external organizations or customers, or information identified through Kikusui assessments, we provide customers with appropriate and timely information, in coordination with relevant organizations, based on our evaluation criteria and response procedures. - Education and Continuous Improvement
We continuously conduct education and awareness activities on product security and strive to improve our product security efforts in response to technological trends and changes in the threat landscape.
*1: We will progressively implement this initiative, starting with products and services planned and developed in the future. For existing products and services, we will also progressively establish security measures and vulnerability response frameworks, taking into consideration factors such as product characteristics, provision status, and the scope of impact. The information on this page does not indicate that all products and services have completed the implementation of security measures at this time. Regarding the specific support status of each product and service, we will inform you on the Kikusui website and other channels as soon as preparations are ready.
2. Product Security Initiatives
Kikusui considers cybersecurity one of its key management priorities and has established promotion frameworks in the areas of Protection of Confidential and Personal Information, Information Security, and Product Security, and is continuously working to strengthen these frameworks.
To promote and manage product security initiatives, Kikusui has established an organizational framework in which relevant departments collaborate within product quality assurance. (PSIRT: Product Security Incident Response Team).
The PSIRT collects, analyzes, and evaluates vulnerability information related to products and services, responds to vulnerabilities, and works to improve product security across the Kikusui Group by considering patches and workarounds, providing information to customers, and coordinating with relevant organizations.
3. Vulnerability Response Process for Kikusui Products
Kikusui has established a product vulnerability reporting contact to receive vulnerability information related to its products.
This contact accepts reports only on undisclosed vulnerabilities in Kikusui products. The PSIRT and relevant departments review the vulnerability information reported to Kikusui and proceed with the response according to the following steps.
- Receipt of vulnerability information
- Review of details and investigation of impact
- Assessment of severity and scope of impact
- Development of a response policy
- Preparation of revised firmware or software, or workarounds
- Provision of information to customers
- Publication of a security advisory
During the investigation, we may ask you to provide additional information on reproduction procedures and the verification environment.
For vulnerabilities originating from third-party products, OSS, or other sources, we may respond in coordination with the relevant vendors or organizations.
Scope of reports accepted
This contact accepts reports only on undisclosed vulnerabilities related to products provided by Kikusui and the associated firmware and software. Reports on vulnerabilities that have already been publicly disclosed, inquiries regarding product defects or operating procedures, and reports concerning services not provided by Kikusui or third-party products alone are outside the scope of this contact. For products for which support has ended, we will determine whether and how to respond on a case-by-case basis, taking the scope of impact into consideration.
Acknowledgment of receipt and progress updates
When we receive a report, as a general rule, we will acknowledge receipt within five business days. We will also provide a control number to be used in subsequent communications.
After the investigation has started, we will provide progress updates as appropriate, generally aiming to do so within about four weeks. We will also contact you again when the response policy has been determined, when the expected timing for providing a fix has been identified, and before the information is publicly disclosed.
4. Vulnerability Information Disclosure Policy
To provide customers with safe and highly reliable products and services, Kikusui appropriately manages vulnerability information related to its products and responds in accordance with the principles of Coordinated Vulnerability Disclosure (CVD).
For vulnerability information reported by customers, security researchers, relevant organizations, and others, Kikusui PSIRT reviews the details and assesses reproducibility, scope of impact, and severity, and prepares patches, firmware updates, or workarounds as necessary. We then disclose the information in a security advisory so that customers can take appropriate measures.
We may list the names of individuals who have contributed to the discovery or resolution of vulnerabilities in the acknowledgments, with their consent.
Timing of disclosure
As a general rule, Kikusui discloses vulnerability information when patches or workarounds are ready for customers to apply. The period until disclosure is determined by taking into consideration the severity of the vulnerability, the scope of affected products, the technical complexity of the fix, and the status of coordination with supply chain stakeholders, and is agreed upon in consultation with the reporter.
If Kikusui determines that early notification is necessary to protect customers, such as when active exploitation has already been confirmed, Kikusui may issue an alert before providing a fix.
Information included in security advisories
Security advisories include an overview of the vulnerability, identifiers, information necessary to identify affected products, potential impact, severity, mitigation measures, publication date, and update date.
Reporting to relevant authorities
When required under applicable laws and regulations, Kikusui may report information concerning vulnerabilities or incidents to relevant authorities.
Kikusui promotes vulnerability management throughout the entire product lifecycle and continuously works to improve product security.
5. Bug bounty program
We do not currently operate a bug bounty (vulnerability rewards) program. However, we welcome good-faith vulnerability reports aimed at improving product security.
6. Vulnerability Reporting Contact
Please report information regarding product vulnerabilities to the contact below.
For inquiries regarding product defects, operating procedures, repairs, or maintenance, please use Kikusui’s general inquiry contact.
If you are unable to use e-mail, you may also contact us regarding vulnerabilities through Kikusui’s general inquiry contact by telephone. In such cases, our representative will ask for the details of your report and forward the information to the Product Security Incident Response Team (PSIRT).
To facilitate a prompt investigation, please provide the following:
- Nickname
- (Required) Contact email address
- (Required) Model (model number)/product name of our product
- Serial number of Kikusui product
- Firmware/software version information of Kikusui product
- (Required) Overview of the vulnerability
- (Required) Potential impact
- Steps to reproduce the vulnerability
- Availability of exploit code
- Reference materials such as logs and screen captures
- Other reference information
Secure communication methods
For reports that include sensitive information, such as proof-of-concept code or configuration information, we may provide guidance on how to exchange information through encrypted means.
Even if encryption is difficult due to constraints on the available communication methods, we will still accept your report.
Contact information
We will make every effort to respond promptly through the relevant department. However, depending on the nature of your inquiry, we may be unable to respond, may require additional time to respond, or may respond in writing or by telephone. We appreciate your understanding.
Please note that inquiries received on Saturdays, Sundays, public holidays, or other company holidays will be answered on or after the next business day.
Reporting Contact: Product Security Incident Response Team (PSIRT)E-mail:psirt@kikusui.co.jp


