Vulnerability Disclosure
Report a Product Vulnerability
We accept reports of vulnerabilities affecting Rigaku Group products through the Vulnerability Report Form below.
Reported vulnerabilities will be handled in accordance with the Vulnerability Disclosure Policy outlined below.
Vulnerability Disclosure Policy
1. Purpose
We accept reports of security vulnerabilities related to our products and services and work collaboratively with reporters to investigate, remediate, and disclose vulnerabilities to help reduce risk to our users.
2. Scope
In Scope: Products and services provided, distributed, or operated by our company and within our operational control.
Out of Scope: Issues arising from third-party services outside our control, excessive load testing, including denial-of-service testing, or testing activities involving data destruction.
3. Reporting a Vulnerability
If you believe you have discovered a security vulnerability, please submit your report through the following contact channel.
Web Form: https://rigaku.com/about/contact-us/vulnerability-disclosure/report
4. Information to Include in Your Report
Please provide the following information where possible. Reports are welcome even if some of the requested information is unavailable.
- Affected Product Information (Product Name, Product ID or Serial Number, and Software Version)
- Description of the vulnerability and its potential impact
- Steps to reproduce the issue, including proof-of-concept code or logs where available and safe to provide
- Contact information (optional)
5. Expectations for Reporters
To minimize risk and disruption, please limit testing activities to the minimum necessary to verify the reported vulnerability.
Please do not access or collect personal information, destroy data, or engage in activities that may disrupt our services, including denial-of-service attacks.
Please coordinate with us before disclosing vulnerability details to third parties prior to remediation or public disclosure.
6. Acknowledgment and Initial Response
Upon receiving a vulnerability report, we will generally acknowledge receipt within five business days.
Our response may be delayed during company-designated holidays and other non-business periods.
We may request additional information as necessary to assess and investigate the reported issue.
We will share investigation and remediation progress with the reporter within reasonable limits.
Products that have reached the end of their support lifecycle may not be eligible for investigation.
7. Information Handling and Disclosure
Prior to remediation and public disclosure, vulnerability information will be shared only with personnel who have a legitimate need to know in order to reduce the risks associated with premature disclosure.
Information will be handled in accordance with applicable legal requirements and any relevant confidentiality obligations, including non-disclosure agreements where applicable.
As a general rule, public disclosure will occur after a security fix or effective mitigation has been made available.
Public disclosures may include affected products and versions, impact and severity information, and mitigation guidance such as update instructions or workarounds.
We will coordinate the timing of public disclosure with the reporter whenever appropriate.
If the risks associated with disclosure are considered to outweigh its benefits, the disclosure schedule may be adjusted to allow users reasonable time to apply available mitigations.
8. Safe Harbor for Good-Faith Reporting
If you comply with this policy and report vulnerabilities in good faith and in a cooperative manner, we will not take adverse action against you solely for reporting a vulnerability in accordance with this policy.
However, this protection does not apply where activities clearly violate applicable laws or infringe the rights of third parties.