Hamamatsu Photonics Group Vulnerability Disclosure Policy

Hamamatsu Photonics Group establishes this policy to ensure the safety of our products, and we will cooperate with reporters of vulnerability information related to our products to appropriately share and disclose such information.

Vulnerability information collection system

As part of the activities of our PSIRT (Product Security Incident Response Team), we gather vulnerability information related to our products from customers and external parties.

If you discover a vulnerability in one of our products, please contact us using the reporting methods described below.

 

*We do not provide any rewards—monetary or otherwise—to reporters of vulnerability information, regardless of the content of the report.

Reporting method

If you discover a vulnerability in one of our products, please contact us through our vulnerability reporting form.

Please include the following information in your report.

 Information to be reported

 ・Relevant product model name

 ・Description of the vulnerability and its scope of impact

 ・Steps to reproduce the vulnerability

 ・Reporter’s name, phone number, and email address

Contact point

Vulnerability Reporting Form

*Personal information will be managed in accordance with our Group Privacy Notice.

*We will notify the reporter within five business days from the date the report is received.

However, responses may be delayed during periods such as year-end/New Year holidays, summer holidays, or Golden Week.

Response to vulnerabilities

When a vulnerability affecting our products is discovered, we will investigate and analyze its impact on the product and determine an appropriate response based on the results. If deemed necessary, we will collaborate with the product design and development departments to implement countermeasures.

Regarding the reporting and disclosure of vulnerability information, we will coordinate with relevant external organizations and respond appropriately.

Notes

In certain cases, we may be unable to respond even if you provide us with vulnerability information.