Product Vulnerability Disclosure Policy

Purpose

This policy stipulates the principles and procedures for receiving and appropriately responding to reports from external parties (hereinafter "the Reporter") regarding security vulnerabilities found in DISCO's (hereinafter "the Company") products. The Company aims to protect users of its products from threats by working with the Reporter to properly check, evaluate, correct, and provide the necessary information regarding the reported product vulnerabilities.

Applicable Products

This policy is applicable to the following products manufactured and provided by the Company:

  • Precision processing equipment
  • Accessory equipment
  • Software provided by the Company for the abovementioned products

Where to Report Product Vulnerabilities

Please report vulnerabilities regarding the Company's products using the following page

The Company's Response and Procedures

The Company will respond to reports in the following order once they are received

  • Confirm the content of the report
  • Identify the applicable product, product version, and scope of impact
  • Evaluate the product vulnerability's reproducibility, severity, and exploitability
  • Consider revisions, mitigation measures, and avoidance measures as needed
  • Provide information to the affected customers
  • Disclose a security advisory (when judged to be required)
  • Record and manage the results of the actions taken

The confirmation results will be shared with the Reporter as needed.

Note: Security advisories will be disclosed using the following method

  • Useful Improvement Information (Technical Newsletter)
  • The length of time required for response varies depending on the severity of the product vulnerability and/or the scope of impact. Please note that although the Company will respond to the issue promptly, depending on the content of the report, it may take some time to reply and we may not able to reply individually. We sincerely appreciate your understanding.

    Regarding the Disclosure Date

    The Company will collaborate with the Reporter to schedule the disclosure date of the product vulnerability information. To minimize the impact on users, we may ask the Reporter not to disclose the information to third parties or to the public until revisions, mitigation measures, and avoidance measures are able to be provided.