HOME >
Vulnerability Disclosure Policy
Last Updated:August 26, 2026
PEGASUS CO., LTD. (hereinafter, “PEGASUS”, “we”, “our”, or “us”) promotes appropriate vulnerability management and Coordinated Vulnerability Disclosure (CVD) to ensure the cybersecurity of products developed, manufactured, or provided by PEGASUS.
We will sincerely accept and evaluate vulnerability information from customers, security researchers, business partners, and other relevant parties, and when deemed necessary, will consider remediation and other responses as well as information disclosure, striving to improve the cybersecurity of our products.
We will continuously identify, assess, remediate, and share information regarding vulnerabilities that may exist in our products.
In responding to vulnerabilities, we will prioritize minimizing the impact on users and will coordinate our response with relevant parties.
We establish a contact point and operational structure responsible for receiving, evaluating, addressing, and disclosing vulnerability reports.
The responsible department carries out the following activities:
This Policy applies to industrial sewing machines, automated machines, and software developed, manufactured, or provided by PEGASUS.
The classification of products subject to maintenance and products not subject to maintenance shall be in accordance with the support policy separately published by PEGASUS.
Vulnerabilities caused by products or software provided by third parties are excluded from the scope of this Policy.
We accept information regarding vulnerabilities through the following contact point.
<Contact Point>
Web Form : https://www.pegasus.co.jp/en/contact/form/index.php?form=psirt
Dedicated Email Address : apparel-psirt@pegasus.co.jp
Reporters are requested to provide the following information to the extent possible.
This contact point is exclusively for vulnerability information.
We cannot respond to inquiries unrelated to vulnerabilities.
We will use personal information such as name, organization, e-mail address, telephone number, and other personal information obtained during vulnerability reporting for the following purposes:
Our handling of personal information shall be in accordance with the separately established Privacy Policy (https://www.pegasus.co.jp/en/privacy/).
We strive to provide communication protection through HTTPS and other appropriate secure communication methods for the safe transmission and reception of vulnerability information.
We request that reporters do not transmit detailed vulnerability information through publicly accessible channels or social media.
We will manage the relevant information as confidential information until the vulnerability is remediated or disclosed.
Access to vulnerability information will be limited to personnel who require it for business purposes, and the following controls will be implemented:
From the perspective of protecting users, we request that both we and reporters refrain from disclosing detailed vulnerability information until the mutually agreed upon disclosure date between PEGASUS and the reporter.
We respond based on the principles of coordinated vulnerability disclosure.
We maintain ongoing communication with reporters, aiming for the following:
We may ask reporters to cooperate by not disclosing vulnerability information before remediation is complete.
It may take some time for us to respond after receiving your vulnerability report.
We will send our response to the designated email address.
There may be delays in our response during company holidays (weekends, national holidays, year-end and New Year holidays, summer holidays, Golden Week, etc.).
Information regarding product vulnerabilities you report will be reviewed and verified by our product development and design departments. If determined to be a new vulnerability, we will coordinate the fix and publication of a security advisory.
For known vulnerabilities, we will conclude our response with the agreement of the reporter.
Please note that we may not provide fixes for products that have reached end of support.
We will conduct a risk assessment of the vulnerability information received and take the following measures as necessary.
We strive for continuous improvement of vulnerability management processes and security measures to enhance product security.
Additionally, this Policy will be reviewed as necessary.
We do not offer rewards regardless of the content of reports.
We will make good faith efforts to respond to vulnerability information we receive; however, we do not guarantee that we will provide fixes, workarounds, or disclose vulnerability information for all reports.
We will respond in compliance with applicable legal obligations; however, we do not guarantee the timing or completion of responses, fixes, or other actions.
Additionally, we may be unable to take action due to product end-of-support status, technical constraints, or other reasons.
We may use vulnerability information we receive for vulnerability response and to improve product safety.
Additionally, we are not liable for costs or other damages incurred in connection with reports.
The Japanese version of this Policy shall be the authoritative text, and in the event of any discrepancy in interpretation between the Japanese version and the English or Chinese versions, the Japanese version shall prevail.
This Policy may be changed without prior notice.
![]()