{"id":4776,"date":"2026-08-31T18:34:32","date_gmt":"2026-08-31T09:34:32","guid":{"rendered":"https:\/\/www.sakicorp.com\/en\/?page_id=4776"},"modified":"2026-09-01T12:33:15","modified_gmt":"2026-09-01T03:33:15","slug":"vulnerability-handling-policy","status":"publish","type":"page","link":"https:\/\/www.sakicorp.com\/en\/vulnerability-handling-policy\/","title":{"rendered":"Product Vulnerability Handling and Disclosure Policy"},"content":{"rendered":"\n<h1 class=\"wp-block-heading h-normal tal wrapper page-first\">Product Vulnerability Handling and Disclosure Policy<\/h1>\n\n\n\n<div class=\"wp-block-group wrapper pc-only is-layout-constrained wp-block-group-is-layout-constrained\"><ul class=\"breadcrumbs wp-block-saki-breadcrumbs yoast-breadcrumbs\"><li><a href=\"https:\/\/www.sakicorp.com\/en\/\">Home<\/a><\/li>  <li>Product Vulnerability Handling and Disclosure Policy<\/li><\/ul><\/div>\n\n\n\n<section class=\"wp-block-group privacy is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--40);margin-bottom:var(--wp--preset--spacing--40)\">\n<h3 class=\"wp-block-heading\">1. Purpose<\/h3>\n\n\n\n<p>Saki Corporation (hereinafter &#8220;the Company&#8221;) establishes this policy to reduce the risk of cyber threats to our customers&#8217; assets and to ensure the safety and integrity of their production environments. This policy defines how vulnerabilities discovered in our products (automated inspection equipment and related software and services) are handled and disclosed.<\/p>\n\n\n\n<p>We are committed to working with security researchers, customers, and coordination organizations to promptly resolve vulnerabilities and provide timely and accurate information to affected users.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--40);margin-bottom:var(--wp--preset--spacing--40)\">\n<h3 class=\"wp-block-heading\">2. Scope<\/h3>\n\n\n\n<p>This policy applies to all products manufactured by the Company that contain digital elements.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Automated inspection equipment<\/li>\n\n\n\n<li>Related inspection software and firmware<\/li>\n\n\n\n<li>Peripheral tools and services provided by the Company<\/li>\n<\/ul>\n\n\n\n<p>For products not manufactured by the Company (such as operating systems or third-party hardware components), please contact the respective manufacturer.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--40);margin-bottom:var(--wp--preset--spacing--40)\">\n<h3 class=\"wp-block-heading\">3. Vulnerability Handling Process<\/h3>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-bottom:var(--wp--preset--spacing--30)\">\n<p>Our vulnerability handling process consists of the following four steps.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-bottom:var(--wp--preset--spacing--30)\">\n<h4 class=\"wp-block-heading\">3.1 Receiving Vulnerability Reports<\/h4>\n\n\n\n<p>We accept vulnerability information regarding our products from all sources, including security researchers, customers, CERT\/CSIRT organizations, and internal teams.<\/p>\n\n\n\n<p>Upon receiving vulnerability information, we coordinate with the relevant technical teams and coordination organizations (JPCERT\/CC, ENISA, and other CERTs) to assess and respond to the issue.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-bottom:var(--wp--preset--spacing--40)\">\n<h4 class=\"wp-block-heading\">Initial Response<\/h4>\n\n\n\n<p>After confirming receipt of vulnerability information, we will send an acknowledgment&nbsp;<strong>within 3 business days<\/strong>. Please note that responses may be delayed during year-end\/New Year holidays, Golden Week, and summer vacation periods.<\/p>\n\n\n\n<div class=\"wp-block-group has-border-color has-tertiary-border-color has-tertiary-background-color has-background is-layout-constrained wp-container-core-group-is-layout-80fb368b wp-block-group-is-layout-constrained\" style=\"border-width:1px;border-radius:6px;padding-top:var(--wp--preset--spacing--30);padding-right:var(--wp--preset--spacing--30);padding-bottom:var(--wp--preset--spacing--30);padding-left:var(--wp--preset--spacing--30)\">\n<p><a href=\"\/en\/contact\/security-incident-report\/\">Report a Product Vulnerability or Security Incident<\/a><\/p>\n\n\n\n<p>This contact point is exclusively for reporting security vulnerabilities in Saki products. For general product inquiries or technical support, please contact your sales representative.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-border-color has-tertiary-border-color has-tertiary-background-color has-background is-layout-constrained wp-container-core-group-is-layout-80fb368b wp-block-group-is-layout-constrained\" style=\"border-width:1px;border-radius:6px;padding-top:var(--wp--preset--spacing--30);padding-right:var(--wp--preset--spacing--30);padding-bottom:var(--wp--preset--spacing--30);padding-left:var(--wp--preset--spacing--30)\">\n<p><strong><strong>Guidelines for Reporters:<\/strong><\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Please provide sufficient information to reproduce the vulnerability<\/li>\n\n\n\n<li>Do not exploit the vulnerability beyond what is necessary for verification<\/li>\n\n\n\n<li>Do not publicly disclose the vulnerability until we have confirmed the fix or agreed on a disclosure timeline<\/li>\n\n\n\n<li>Do not access, modify, or delete others&#8217; data during testing<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"border-style:none;border-width:0px\">\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-bottom:var(--wp--preset--spacing--30)\">\n<h4 class=\"wp-block-heading\">3.2 Vulnerability Analysis and Assessment<\/h4>\n\n\n\n<p>We determine whether a reported issue constitutes a valid vulnerability based on the following criteria:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Whether it may affect the security of our products (adverse impact on confidentiality, integrity, or availability)<\/li>\n\n\n\n<li>Whether it can be reproduced on our products under realistic conditions<\/li>\n\n\n\n<li>Whether it is previously unknown or unaddressed<\/li>\n<\/ul>\n\n\n\n<p>If confirmed as a valid vulnerability, we assess the severity&nbsp;<strong>with reference to CVSS (Common Vulnerability Scoring System)<\/strong>&nbsp;and determine remediation priority taking into account the product-specific usage environment.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-bottom:var(--wp--preset--spacing--30)\">\n<h4 class=\"wp-block-heading\">3.3 Remediation<\/h4>\n\n\n\n<p>Appropriate remediation measures are implemented based on the severity assessment.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Critical \/ High Severity:<\/strong>&nbsp;Patch or update provided as soon as practically possible (target: within 90 days)<\/li>\n\n\n\n<li><strong>Medium Severity:<\/strong>&nbsp;Addressed in the next scheduled release (target: within 120 days)<\/li>\n\n\n\n<li><strong>Low Severity:<\/strong>&nbsp;Addressed in a future release cycle<\/li>\n<\/ul>\n\n\n\n<p>When immediate patching is not feasible, we provide guidance on workarounds or temporary mitigations to reduce the impact.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-bottom:var(--wp--preset--spacing--40)\">\n<h4 class=\"wp-block-heading\">3.4 Vulnerability Disclosure<\/h4>\n\n\n\n<p>Vulnerability information is provided to customers based on the principles of Coordinated Vulnerability Disclosure (CVD), at an appropriate time determined in consultation with the reporter and relevant organizations.<\/p>\n\n\n\n<p>Disclosure methods:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Individual notification to affected customers through service representatives<\/li>\n\n\n\n<li>Reporting to CERT\/CSIRT organizations where required by regulation<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--40);margin-bottom:var(--wp--preset--spacing--40)\">\n<h3 class=\"wp-block-heading\">4. Safe Harbor (Reporter Protection)<\/h3>\n\n\n\n<p>The Company will not take legal action against individuals who:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Report vulnerabilities in good faith and in accordance with this policy<\/li>\n\n\n\n<li>Make reasonable efforts to avoid privacy violations, data destruction, or service disruption<\/li>\n\n\n\n<li>Do not exploit the vulnerability beyond what is necessary for verification<\/li>\n<\/ul>\n\n\n\n<p>We consider security research conducted in accordance with this policy to be legitimate activity and will not pursue legal claims against good-faith reporters.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--40);margin-bottom:var(--wp--preset--spacing--40)\">\n<h3 class=\"wp-block-heading\">5. Regulatory Compliance<\/h3>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--30);margin-bottom:var(--wp--preset--spacing--30)\">\n<p>This policy supports compliance with the following regulations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>EU Cyber Resilience Act (CRA)<\/strong>&nbsp;\u2014 Regulation (EU) 2024\/2847, Annex I Part II(5): Obligation to establish and enforce a coordinated vulnerability disclosure policy<\/li>\n\n\n\n<li><strong>EU Machinery Regulation<\/strong>&nbsp;\u2014 (EU) 2023\/1230, Annex III Section 1.1.9: Protection against corruption<\/li>\n\n\n\n<li><strong>IEC 62443 Series<\/strong>&nbsp;\u2014 Security for industrial automation and control systems<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--40);margin-bottom:var(--wp--preset--spacing--40)\">\n<h3 class=\"wp-block-heading\">6. <strong>Continuous Improvement<\/strong><\/h3>\n\n\n\n<p>We continuously review our efforts under this policy and strive for more effective vulnerability management and faster response. This policy may be revised without prior notice. Any revisions will be announced on this page.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--50);margin-bottom:var(--wp--preset--spacing--50)\">\n<h3 class=\"wp-block-heading\">Revision History<\/h3>\n\n\n\n<div class=\"wp-block-group is-content-justification-left is-layout-constrained wp-container-core-group-is-layout-5b3d42a2 wp-block-group-is-layout-constrained\">\n<figure class=\"wp-block-table is-style-regular\"><table class=\"has-fixed-layout\" style=\"border-width:1px\"><thead><tr><th>Date<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td>August 2026<\/td><td>First edition published<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Product Vulnerability Handling and Disclosure Policy 1. Purpose Saki Corporation (hereinafter &#8220;the Company&#8221;) establishes this policy to reduce the risk of cyber threats to our customers&#8217; assets and to ensure the safety and integrity of their production environments. This policy defines how vulnerabilities discovered in our products (automated inspection equipment and related software and services) are handled and disclosed. We are committed to working with security researchers, customers, and coordination organizations to promptly resolve vulnerabilities and provide timely and accurate information to affected users. 2. Scope This policy applies to all products manufactured by the Company that contain digital elements. For products not manufactured by the Company (such as operating systems or third-party hardware components), please contact the respective manufacturer&#8230;.<\/p>\n","protected":false},"author":8,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-4776","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.sakicorp.com\/en\/wp-json\/wp\/v2\/pages\/4776","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sakicorp.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.sakicorp.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.sakicorp.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sakicorp.com\/en\/wp-json\/wp\/v2\/comments?post=4776"}],"version-history":[{"count":1,"href":"https:\/\/www.sakicorp.com\/en\/wp-json\/wp\/v2\/pages\/4776\/revisions"}],"predecessor-version":[{"id":4777,"href":"https:\/\/www.sakicorp.com\/en\/wp-json\/wp\/v2\/pages\/4776\/revisions\/4777"}],"wp:attachment":[{"href":"https:\/\/www.sakicorp.com\/en\/wp-json\/wp\/v2\/media?parent=4776"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}