Product Vulnerability Handling and Disclosure Policy
1. Purpose
Saki Corporation (hereinafter “the Company”) establishes this policy to reduce the risk of cyber threats to our customers’ assets and to ensure the safety and integrity of their production environments. This policy defines how vulnerabilities discovered in our products (automated inspection equipment and related software and services) are handled and disclosed.
We are committed to working with security researchers, customers, and coordination organizations to promptly resolve vulnerabilities and provide timely and accurate information to affected users.
2. Scope
This policy applies to all products manufactured by the Company that contain digital elements.
- Automated inspection equipment
- Related inspection software and firmware
- Peripheral tools and services provided by the Company
For products not manufactured by the Company (such as operating systems or third-party hardware components), please contact the respective manufacturer.
3. Vulnerability Handling Process
Our vulnerability handling process consists of the following four steps.
3.1 Receiving Vulnerability Reports
We accept vulnerability information regarding our products from all sources, including security researchers, customers, CERT/CSIRT organizations, and internal teams.
Upon receiving vulnerability information, we coordinate with the relevant technical teams and coordination organizations (JPCERT/CC, ENISA, and other CERTs) to assess and respond to the issue.
Initial Response
After confirming receipt of vulnerability information, we will send an acknowledgment within 3 business days. Please note that responses may be delayed during year-end/New Year holidays, Golden Week, and summer vacation periods.
Report a Product Vulnerability or Security Incident
This contact point is exclusively for reporting security vulnerabilities in Saki products. For general product inquiries or technical support, please contact your sales representative.
Guidelines for Reporters:
- Please provide sufficient information to reproduce the vulnerability
- Do not exploit the vulnerability beyond what is necessary for verification
- Do not publicly disclose the vulnerability until we have confirmed the fix or agreed on a disclosure timeline
- Do not access, modify, or delete others’ data during testing
3.2 Vulnerability Analysis and Assessment
We determine whether a reported issue constitutes a valid vulnerability based on the following criteria:
- Whether it may affect the security of our products (adverse impact on confidentiality, integrity, or availability)
- Whether it can be reproduced on our products under realistic conditions
- Whether it is previously unknown or unaddressed
If confirmed as a valid vulnerability, we assess the severity with reference to CVSS (Common Vulnerability Scoring System) and determine remediation priority taking into account the product-specific usage environment.
3.3 Remediation
Appropriate remediation measures are implemented based on the severity assessment.
- Critical / High Severity: Patch or update provided as soon as practically possible (target: within 90 days)
- Medium Severity: Addressed in the next scheduled release (target: within 120 days)
- Low Severity: Addressed in a future release cycle
When immediate patching is not feasible, we provide guidance on workarounds or temporary mitigations to reduce the impact.
3.4 Vulnerability Disclosure
Vulnerability information is provided to customers based on the principles of Coordinated Vulnerability Disclosure (CVD), at an appropriate time determined in consultation with the reporter and relevant organizations.
Disclosure methods:
- Individual notification to affected customers through service representatives
- Reporting to CERT/CSIRT organizations where required by regulation
4. Safe Harbor (Reporter Protection)
The Company will not take legal action against individuals who:
- Report vulnerabilities in good faith and in accordance with this policy
- Make reasonable efforts to avoid privacy violations, data destruction, or service disruption
- Do not exploit the vulnerability beyond what is necessary for verification
We consider security research conducted in accordance with this policy to be legitimate activity and will not pursue legal claims against good-faith reporters.
5. Regulatory Compliance
This policy supports compliance with the following regulations:
- EU Cyber Resilience Act (CRA) — Regulation (EU) 2024/2847, Annex I Part II(5): Obligation to establish and enforce a coordinated vulnerability disclosure policy
- EU Machinery Regulation — (EU) 2023/1230, Annex III Section 1.1.9: Protection against corruption
- IEC 62443 Series — Security for industrial automation and control systems
6. Continuous Improvement
We continuously review our efforts under this policy and strive for more effective vulnerability management and faster response. This policy may be revised without prior notice. Any revisions will be announced on this page.
Revision History
| Date | Description |
|---|---|
| August 2026 | First edition published |
