GENERAL Inc. and its group companies (the "Group") collect and disclose vulnerability information on its products according to ISO/IEC 29147 through the following process.
The Group collects vulnerability information on its products from external security researchers and coordinating bodies to improve the information security quality of its products.
To report any vulnerabilities of our product, please contact us through the Vulnerability Reporting Desk via our website at the link below.
When a new vulnerability is confirmed in its products, the Group will release a security advisory to enable its customers to take appropriate countermeasures. Once the advisory is ready for release, we will coordinate the release date with the reporter and other stakeholders. After that, we will publish the advisory on our website at the link below, with an assigned CVE number.
The Group does not run any bug bounty programs.
The Group values coordinated and responsible vulnerability disclosure and appreciates reports submitted in good faith for the purpose of improving the security of our products and services.
When a vulnerability is reported in good faith and in accordance with our vulnerability reporting procedures and responsible disclosure principles, the Group will not initiate legal action or seek civil liability against the reporter solely for the act of reporting the vulnerability.
This safe harbor does not apply to activities that involve intentional misconduct, infringement of third-party rights, disruption of services, unauthorized access beyond what is necessary to demonstrate the vulnerability, or violations of applicable laws and regulations.