MENU
  • HOMEHOME

  • HOME >

  •   Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Last Updated:August 26, 2026

PEGASUS CO., LTD. (hereinafter, “PEGASUS”, “we”, “our”, or “us”) promotes appropriate vulnerability management and Coordinated Vulnerability Disclosure (CVD) to ensure the cybersecurity of products developed, manufactured, or provided by PEGASUS.
We will sincerely accept and evaluate vulnerability information from customers, security researchers, business partners, and other relevant parties, and when deemed necessary, will consider remediation and other responses as well as information disclosure, striving to improve the cybersecurity of our products.

1.Basic Policy

We will continuously identify, assess, remediate, and share information regarding vulnerabilities that may exist in our products.
In responding to vulnerabilities, we will prioritize minimizing the impact on users and will coordinate our response with relevant parties.

2.Vulnerability Management System

We establish a contact point and operational structure responsible for receiving, evaluating, addressing, and disclosing vulnerability reports.
The responsible department carries out the following activities:

  • Receiving and recording vulnerability information
  • Technical evaluation and impact analysis
  • Development of remediation plans
  • Implementation and verification of remediation measures
  • Communication with stakeholders
  • Issuance of security advisories and disclosure of vulnerability information as necessary

3.Scope

This Policy applies to industrial sewing machines, automated machines, and software developed, manufactured, or provided by PEGASUS.
The classification of products subject to maintenance and products not subject to maintenance shall be in accordance with the support policy separately published by PEGASUS.
Vulnerabilities caused by products or software provided by third parties are excluded from the scope of this Policy.

4.Contact for Vulnerability Information

We accept information regarding vulnerabilities through the following contact point.

<Contact Point>
Web Form : https://www.pegasus.co.jp/en/contact/form/index.php?form=psirt
Dedicated Email Address : apparel-psirt@pegasus.co.jp
Reporters are requested to provide the following information to the extent possible.

  • Product Name
  • Software Version
  • Details of the Vulnerability
  • Steps to Reproduce
  • Potential Impact
  • Contact Information (Name, Organization, E-mail Address, Telephone Number)

This contact point is exclusively for vulnerability information.
We cannot respond to inquiries unrelated to vulnerabilities.

5.Handling of Personal Information

We will use personal information such as name, organization, e-mail address, telephone number, and other personal information obtained during vulnerability reporting for the following purposes:

  • Communication regarding vulnerability response
  • Verification and investigation of reported content
  • Record management related to vulnerability response
  • Other tasks necessary for vulnerability response

Our handling of personal information shall be in accordance with the separately established Privacy Policy (https://www.pegasus.co.jp/en/privacy/).

6.Secure Communication

We strive to provide communication protection through HTTPS and other appropriate secure communication methods for the safe transmission and reception of vulnerability information.
We request that reporters do not transmit detailed vulnerability information through publicly accessible channels or social media.

7.Prevention of Information Leakage

We will manage the relevant information as confidential information until the vulnerability is remediated or disclosed.
Access to vulnerability information will be limited to personnel who require it for business purposes, and the following controls will be implemented:

  • Access permission management
  • Protection of communication channels and shared media
  • Storage in approved systems
  • Maintenance of sharing records

From the perspective of protecting users, we request that both we and reporters refrain from disclosing detailed vulnerability information until the mutually agreed upon disclosure date between PEGASUS and the reporter.

8.Coordinated Vulnerability Disclosure

We respond based on the principles of coordinated vulnerability disclosure.
We maintain ongoing communication with reporters, aiming for the following:

  • Acknowledgment of report receipt
  • Sharing of investigation status
  • Notification of planned countermeasures
  • Coordination of disclosure timing

We may ask reporters to cooperate by not disclosing vulnerability information before remediation is complete.

9.Our Response

It may take some time for us to respond after receiving your vulnerability report.
We will send our response to the designated email address.
There may be delays in our response during company holidays (weekends, national holidays, year-end and New Year holidays, summer holidays, Golden Week, etc.).
Information regarding product vulnerabilities you report will be reviewed and verified by our product development and design departments. If determined to be a new vulnerability, we will coordinate the fix and publication of a security advisory.
For known vulnerabilities, we will conclude our response with the agreement of the reporter.
Please note that we may not provide fixes for products that have reached end of support.

10.Vulnerability Assessment and Remediation

We will conduct a risk assessment of the vulnerability information received and take the following measures as necessary.

  • Software updates
  • Configuration Changes
  • Provision of workarounds
  • Issuance of security advisories

11.Continuous Improvement

We strive for continuous improvement of vulnerability management processes and security measures to enhance product security.
Additionally, this Policy will be reviewed as necessary.

12.Rewards

We do not offer rewards regardless of the content of reports.

13.Disclaimer

We will make good faith efforts to respond to vulnerability information we receive; however, we do not guarantee that we will provide fixes, workarounds, or disclose vulnerability information for all reports.
We will respond in compliance with applicable legal obligations; however, we do not guarantee the timing or completion of responses, fixes, or other actions.
Additionally, we may be unable to take action due to product end-of-support status, technical constraints, or other reasons.
We may use vulnerability information we receive for vulnerability response and to improve product safety.
Additionally, we are not liable for costs or other damages incurred in connection with reports.

14.Language

The Japanese version of this Policy shall be the authoritative text, and in the event of any discrepancy in interpretation between the Japanese version and the English or Chinese versions, the Japanese version shall prevail.

15.Revision

This Policy may be changed without prior notice.

ページの先頭へ

close