Please direct any queries, in Japanese or English, to: sales@miwa-lock.co.jp
Vulnerability Disclosure Policy
MIWA LOCK Co., Ltd. ("MIWA LOCK", "we", "us", or "our") is committed to maintaining the security and quality of its products and helping customers use them with confidence. In accordance with ISO/IEC 29147, we have established the following process for receiving, assessing, addressing, and disclosing information concerning security vulnerabilities.
If you discover a security vulnerability affecting a MIWA LOCK product, please report it to us at sales@miwa-lock.co.jp.
Our vulnerability reporting contact accepts security vulnerability reports relating to MIWA LOCK products, including products that can connect to the Internet or a network. We are unable to respond to reports concerning products not manufactured by MIWA LOCK or to inquiries unrelated to vulnerability reporting, such as job-seeking or sales solicitations.
We handle vulnerability and security incident response in accordance with applicable laws and regulations, including the EU Cyber Resilience Act (CRA). Where required, vulnerabilities known to be actively exploited and significant security incidents will be reported to the relevant authorities, including the appropriate CSIRT, and other organizations as required in accordance with applicable reporting obligations.
To help us investigate your report, please provide as much of the following information as possible:
・Product name, model number, and software/firmware version ・Vulnerability type or classification, including the applicable Common Weakness Enumeration (CWE), if known ・Environment or system configuration in which the vulnerability was reproduced ・Date and time of reproduction and the affected unit's serial number or other identifying information ・Step-by-step instructions for reproducing the issue ・Proof-of-concept code or exploit code, where applicable ・Potential security impact of the vulnerability ・Your contact details, including your name or handle and email address
We will normally acknowledge receipt of a vulnerability report within seven business days of receiving it, excluding extended holiday periods such as summer holidays and the year-end/New Year holidays.
Personal information provided by a reporter will be handled responsibly and used only for responding to and maintaining records of the vulnerability report. Please see our Privacy Policy for further details.
Unless otherwise permitted by applicable law, you may not reproduce, reuse, or otherwise use all or part of our response without our prior permission.
MIWA LOCK does not currently operate a vulnerability reward or bug bounty program.
When we receive a vulnerability report, the relevant product design and development teams will assess the scope and severity of the issue and determine its priority through a triage process. Where appropriate, we may use recognized risk assessment methods, such as CVSS, to evaluate the potential impact. Based on the results of the assessment, we will consider and implement appropriate mitigation or remediation measures.
After acknowledging receipt of a report, we will normally provide the reporter with a progress update every 30 days until the response process is completed. Communications with the reporter will generally take place by email. To reduce the risk of sensitive vulnerability information being disclosed to third parties, we will take appropriate steps to protect such information during our communications.
MIWA LOCK follows a Coordinated Vulnerability Disclosure (CVD) approach and will coordinate, as appropriate, with the reporter and relevant organizations regarding the timing and content of public disclosure.
Depending on the scope and risk of a vulnerability, we may notify affected users. The method of notification may include publication on our website, email notification, or other appropriate means.
We do not intend to take legal action against individuals or organizations that report vulnerabilities in good faith and in accordance with this Policy.
If the same vulnerability is reported independently by multiple individuals or organizations, the first person or organization to report the vulnerability will be treated as the original reporter.
To help protect customers and users, we ask all relevant parties not to disclose information about a reported vulnerability—including its details, existence, or response status—to third parties until the vulnerability has been addressed and the necessary information has been officially disclosed.
While we make reasonable efforts to ensure that the information published on this website is accurate and up to date, we do not guarantee the accuracy, usefulness, completeness, reliability, or security of the information or any mitigation measures described.
Any patches or other updates we provide may not function perfectly in every environment. In addition, depending on product support periods and product specifications, we cannot guarantee that a corrective patch will be issued for every reported vulnerability.
MIWA LOCK shall not be liable for any direct or indirect damages arising from the use of this website or the information published on it.
The structure, content, URLs, and availability of this website may be changed, removed, suspended, or discontinued without prior notice. Although we will make reasonable efforts to restore service promptly in the event of delays, interruptions, or suspension, MIWA LOCK shall not be liable for any damages resulting from such events.