Product Security

Aratas Product Security Incident Response Team (PSIRT)

Aratas PSIRT collects a wide range of security vulnerability information of our products and services. Aratas Corporation promptly takes countermeasures in response to discovered vulnerabilities in cooperation with government agencies.
If you find a vulnerability in one of our products or services, please report it to Aratas PSIRT.

Security vulnerability report

Aratas PSIRT collects a wide range of security vulnerability information on our products and services. Aratas Corporation promptly takes countermeasures in response to discovered vulnerabilities in cooperation with government agencies.

If you find a vulnerability in one of our products or services, please report it to Aratas PSIRT.
Acknowledgments to those who have contributed to the discovery or resolution of the vulnerability disclosed on our website will be included in the advisory with their prior consent. If more than one person reports the same vulnerability information, Aratas Corporation will acknowledge the first reporter.

Aratas PSIRT contact:
Email address: psirt_contact-Aratas-cc-j[at]omron.com
 *Please remember to change [at] to @ when you send us an email.

Please provide the following information. (* Required)

Customer Information

  • (1) Name*
  • (2) Phone number
  • (3) Company/Organization
  • (4) Email address*

Vulnerability Information

  • (5) Product or service identification information* (such as name, model, type number, or version)
  • (6) Affected version(s)
  • (7) Details of vulnerability* (Please describe the vulnerability as specific as possible.)
  • (8) Steps to Reproduce
  • Responses may take a long time depending on the content of the report.
  • Responses are made on the next business day or later of Aratas Corporation for the reports sent on weekends, national holidays, new year holidays or summer holidays.

Handling of Personal Information for Customers

  1. Aratas Corporation will manage and handle, in an appropriate manner, the information including personal information which is received by email concerning vulnerability to our product(s) or service(s).
  2. All or part of our response is protected by laws, including copyright law. Any disclosure, reproduction, copying and/or secondary use is prohibited without permission from Aratas Corporation.
  3. Aratas Corporation will take appropriate safety measures to manage personal information provided by customers, such as name, email address and phone number, using email (hereafter 'Customer's Personal Information') and will not disclose or provide it to third parties without consent of the customer except in the following cases:
    • For the purpose of appropriate handling of, and response to, the vulnerability information provided by the customer, Aratas Corporation may make joint use of the content of the vulnerability and relevant Customer's Personal Information with its group companies in Japan and abroad, group companies OMRON corporation in Japan and abroad, joint research partners, subcontractors, dealers, distributors and agents, transferring it in written form or via electronic media.
    • Aratas Corporation may contract out a part of or the entire handling of the obtained Customer's Personal Information within the scope necessary to achieve the purpose of use described above.
  4. Aratas Corporation will use Customer's Personal Information to handle or confirm the content of the vulnerability. For the purpose of that, Aratas Corporation may keep records of the content and response history on the report.
  5. Minor customers are asked to provide any information including Customer's Personal Information with the consent of their parent(s) or guardian(s).

For further information regarding privacy policy and the handling of personal information, please refer to https://components.omron.com/eu-en/privacy-policy.

Product security policy

Basic policy on product security

Aratas Corporation will strive to supply secure products and services for customer’s safety and security.
For this purpose, Aratas Corporation will conduct product security activities to implement security measures against cyberattacks.

Product security activity system

Aratas Corporation has established a system to promote product security activities.
Regarding vulnerability response for products and services, Aratas Corporation will establish and operate a PSIRT (Product Security Incident Response Team).

Product security activities

  1. Provision of secure products and services
    Aratas Corporation will conduct activities throughout the product lifecycle (planning, development, operation/maintenance, and disposal) to implement security measures against cyberattacks.
  2. Vulnerability response regarding the products and services
    Aratas Corporation will extensively collect information on vulnerabilities regarding our products and/or services, then promptly take countermeasures in response to discovered vulnerabilities.
  3. Security incident response for the products and services
    In case of a security incident by a cyberattack to any of our products or services, Aratas Corporation will promptly organize a system to manage it and strive to make reports necessary to both inside and outside the company, disclose related information, investigate its causes, and prevent a recurrence.
  4. Provision of security information regarding the products and services
    During a vulnerability response or security incident response, Aratas Corporation will provide information to our customers as needed in cooperation with government agencies.
    Regarding information disclosure, Aratas Corporation will announce the vulnerability information and the countermeasures against the vulnerability on our website or through JVN (Japan Vulnerability Notes). Aratas Corporation may contact a specific customer directly through our sales department if Aratas Corporation determines that the vulnerability affects that customer.

Vulnerability Information Disclosure Policy

Aratas Vulnerability Information Disclosure Policy

Aratas Corporation collects information on security vulnerabilities affecting its products and services from a wide range of sources and addresses such information appropriately to help ensure the safety and security of its customers. Vulnerabilities reported by external parties are handled in accordance with this policy.

Scope

This policy applies to all products and services provided to customers by Aratas Corporation.

Vulnerability Reporting Contact

If you discover a potential vulnerability in products and services provided by Aratas Corporation, please report it to the Aratas Product Security Incident Response Team (PSIRT).
Information provided by reporters will be appropriately protected and used solely for vulnerability handling activities.

Aratas PSIRT contact:
Email address: psirt_contact-Aratas-cc-j[at]omron.com
 *Please remember to change [at] to @ when you send us an email.

When submitting a vulnerability report, please provide the following information.

  • Product or service identification information (such as name, model, type number, or version)
  • Affected version(s)
  • Details of vulnerability
  • Steps to Reproduce

Communication with Reporters

After confirming receipt of vulnerability information, Aratas Corporation will acknowledge receipt to the reporter by email within five business days after receipt, based on business calendar of Aratas Corporation.
Note: Aratas Corporation may have extended company holidays around the year-end and New Year period, early May, mid-August, and late September.

After a report has been submitted, subsequent communication with the reporter will be conducted by email. If the reporter wishes to submit sensitive information, Aratas Corporation will provide instructions for submission by PGP-encrypted email.

Aratas Corporation will maintain ongoing communication with the reporter throughout the vulnerability handling process until the issue is resolved, including requests for additional information and progress updates.
Communications sent by Aratas Corporation to the reporter, including responses of Aratas Corporation, are protected by copyright law and other applicable laws and regulations. Please do not reproduce, publish, or reuse such communications without prior permission of Aratas Corporation.

Vulnerability Information Disclosure Policy

Timing of Disclosure

When Aratas Corporation publishes a security advisory, it will do so in accordance with the principles of Coordinated Vulnerability Disclosure. Once remediation measures, such as security patches, mitigation measures, or workarounds, are ready, Aratas Corporation will coordinate the disclosure date with relevant stakeholders, including the reporter, prior to public disclosure. At the time of publication, Aratas Corporation will also submit a vulnerability report to JPCERT/CC (Japan Computer Emergency Response Team Coordination Center) and, where necessary, to overseas CERT organizations.

Information to be Disclosed

The security advisory will include the following information.

  • Vulnerability summary
  • Affected products or services, including product or service name, model, type number, version, and other relevant identifiers
  • Impact
  • CVE ID (In applicable case(s))
  • Vulnerability severity
  • Remediation information, including fixed versions, workarounds, or mitigation measures
  • Publication and update dates
Publication Channels

Security advisories will be published on the website of Aratas Corporation, JVN (Japan Vulnerability Notes), and other appropriate channels.

Acknowledgment

With their prior consent, Aratas Corporation will acknowledge individuals or organizations that have contributed to the discovery or resolution of a vulnerability in the relevant advisory published on the website of Aratas Corporation.
If Aratas Corporation receives information from more than one reporter about a vulnerability that Aratas Corporation determines to be the same, Aratas Corporation will acknowledge the first reporter.

Vulnerability information / Security advisory

Security advisories will be published on this page when they are ready for public disclosure.