SECURITY

Product Vulnerability Reporting Desk

Security Policy

Basic Principles

Kawasaki Robot Service Co., Ltd. ("the Company") is committed to ensuring the cybersecurity of products and services so that customers can use them with confidence. The Company actively works to maintain and improve cybersecurity throughout the product lifecycle to prevent malicious cyberattacks by third parties from causing product or service malfunctions, unauthorized modifications, or information tampering.

Purpose and Scope

The purpose of this policy is to ensure that all executives and employees of the Company recognize the importance of cybersecurity for products and services, and act accordingly in their business activities. The policy covers products that handle information, as well as other products that may be susceptible to cyberattacks.

Compliance with Laws and Regulations (Legal Compliance)

The Company complies with all applicable cybersecurity laws and regulations relating to its products and services.

Product Security Management Framework

The Company has set up a Product Security Incident Response Team (PSIRT) to ensure that cybersecurity is managed systematically and continuously throughout the entire product lifecycle.

Security-Conscious Product Development

The Company promotes product development with a strong focus on security for potential cyber threats to the assets that require protection including product functions and stored information during the planning and development phases, and they are evaluated to ensure that no security vulnerabilities are introduced into the product.

Provide Education and Training

The Company is committed to collecting the latest information and providing ongoing education and training to employees to enhance their knowledge and technical expertise related to product security.

Vulnerability Disclosure Policy

Vulnerability Handling Process

The Vulnerability Reporting Desk only accepts reports for vulnerabilities related to our products. We would like to assure you that reported vulnerability information will be investigated by the relevant departments within the Company. We are committed to considering appropriate response measures. We will consider countermeasures and prepare remediation procedures, corrective software, or mitigation procedures as appropriate if the vulnerability is determined to affect our products.

Publication of Security Advisories

The Security Advisory will be published on our website as soon as preparations for disclosure are complete, enabling customers to take appropriate countermeasures if a reported issue is confirmed to be a vulnerability affecting our products. We will coordinate the disclosure date with the reporter in accordance with the principle of coordinated disclosure when disclosing vulnerability information.