Mitutoyo PSIRT
Product Vulnerability Disclosure Policy
February 2, 2026
Mitutoyo Corporation accepts vulnerability reports from external sources and handles them responsibly to enhance the security of our products and services.
1. Mitutoyo PSIRT
We have established a PSIRT (Product Security Incident Response Team) to address the security of our products and services. The PSIRT is responsible for handling everything from the receipt of vulnerability reports to the completion of the response, working quickly in coordination with relevant departments.
2. Scope
This policy covers the products and services that we provide to our customers.
3. Permitted Tests and Prohibitions
Vulnerability testing on our systems should be conducted legally and in good faith. Specifically, the following actions are strictly prohibited:
- Unauthorized Access:Intrusion or bypassing authentication into systems not explicitly permitted by our company.
- Service Disruption (DoS/DDoS):Mass access or overload attacks intended to halt the system.
- Improper Handling of Personal Information:Disclosing personally identifiable information obtained during testing to third parties.
- Other Illegal Acts:Activities involving copyright infringement, privacy rights violations, unauthorized operations, etc.
4. Reporting Method
Vulnerability reports are accepted through the dedicated web form set up by our company (Report Product Security Issue). When reporting, please provide as much of the following information as possible:
- Reporter information:name, affiliation, contact details, etc.
- Overview of the vulnerability:description of the issue and circumstances of discovery.
- Name and version of the affected product/service:identification of the affected system.
- Reproduction steps and technical information:Steps to reproduce the vulnerability, sample code, etc.
- Potential impact:risk or impact if the vulnerability is exploited.
The above information is necessary for prompt analysis and response.
5. Post-Report Actions
After receiving a report, we will, in principle, reply with an acknowledgement of receipt within three business days. During the investigation and corrective action process, we strive to share progress with the reporter as much as possible, maintaining a transparent approach. If the presence of the vulnerability is confirmed, appropriate corrective measures (such as product updates or configuration changes) will be taken, and if necessary, alerts and avoidance measures will be published on our website. After the correction is completed, the reporter will be notified of the correction details and impact range.
6. Legal Protection
We will not recommend or pursue any legal action against reporters who conduct security testing in good faith and in accordance with this policy. Reporters are expected to conduct tests at their own risk and report in compliance with this policy. Information obtained through methods not permitted by we will not be considered as reported under this policy.
7. Bug Bounty and Credit
We do not have a bug bounty program and there is no monetary reward for reporting vulnerabilities. Additionally, we do not publish the name or organization of reporters in public advisories or reports. We express gratitude to the reporters, but please understand that no reward or publication will be made.
8. Policy Updates
This policy may be reviewed and revised as necessary. The latest version will be published on our website, reflecting any updates. Based on the above policy, we will strive to provide safe products and services in cooperation with the reporter.