Vulnerability Disclosure Policy
1. Purpose
Max Corporation and its group companies (hereinafter, “the Company”) strive to ensure that our customers can use our products and services safely and securely, and to appropriately maintain product security throughout the entire lifecycle of our products and services.
The Company publishes information on vulnerabilities discovered in our products and services according to the following process.
2. Collection of Vulnerability Information
The Company collects information regarding vulnerabilities in its products and services. If a vulnerability is discovered in the Company’s products, please contact the Company via the Vulnerability Reporting Contact on the website (English only) under “Report a Product Security Issue.”
When reporting a vulnerability, please provide the following information:
- Product name and software version
- Type of vulnerability
- Impact of the vulnerability
- Steps to reproduce the vulnerability
The Company will acknowledge receipt of the report within seven business days from the date of receipt (excluding long holidays such as summer holidays and year-end/New Year holidays).
For information on how the Company handles the personal information of reporters, please refer to the Privacy Policy on the Company’s website.
3. Excluded Vulnerability Information
The Company does not accept the following types of reports:
- Vulnerabilities in products that are no longer supported or trial versions
- Social engineering attacks (e.g., phishing attacks)
- Denial-of-Service (DoS) attacks caused by large numbers of requests
- Reports based solely on the output of automated tools
- Weaknesses in TLS configuration (e.g., weak cipher suites, TLS 1.0 support)
- Vulnerabilities that cannot be reproduced
- Vulnerabilities that have already been publicly disclosed
- Reports indicating non-compliance with the security guidelines’ “best practices”"
4. Investigation and Remediation
The Company promptly investigates vulnerabilities reported in its products and services through the relevant departments. As necessary, the Company coordinates with appropriate organizations to implement suitable countermeasures.
The Company may request additional information from the reporter if required. The reporter will be kept informed as appropriate until the response is completed.
5. Disclosure of Vulnerability Information
Once countermeasures for vulnerabilities in the Company’s products and services are completed, the Company will coordinate with relevant organizations to schedule the disclosure of vulnerability information. This information, including details of the vulnerabilities and corresponding countermeasures, will be published on the Company’s website and on related sites of the coordinating organizations.
In addition, in accordance with applicable laws and regulations, the Company will report to external security authorities and coordinating organizations as required.
6. Rewards
The Company does not provide any rewards, regardless of the content of the report.