Traffic Sim Co., Ltd. (“we” or “us”) accepts information about security weaknesses in our products (“vulnerabilities”) from external parties and responds to it responsibly, so that our customers can use our products with confidence. This policy describes how to report a vulnerability to us and what we do from the time we receive a report until it is resolved.

Scope

This policy covers the products and services that we develop and provide (for example, the Current Monitoring System EnergyGazer).

The following are outside the scope of this policy:

  • Issues caused by modifications made by the customer, or by software not provided by us
  • Issues with our internal systems or this website (please use our Contact page)

Please note that we may not be able to provide countermeasures for products whose support period has ended.

How to Report

Please use the Vulnerability Report Form at the bottom of this page. Including the following information will help us investigate quickly:

  • Product name, model number, and software version
  • Description of the vulnerability and its possible impact if exploited
  • Steps to reproduce it (environment, settings, tools used, etc.)

The form is available in Japanese only. You may fill it in in English.

The form does not accept file attachments. If you need to send us materials, we will explain how when we acknowledge your report.

For questions about product operation or malfunctions, please use our Contact page.

Our Requests to Reporters

  • Please comply with applicable laws, and conduct your research only on devices and environments that you own or manage.
  • Do not access other people’s devices or services, disrupt services, or obtain, modify, or delete data.
  • To protect our users, please do not disclose the details of a vulnerability to third parties until we have published countermeasures.

From Report to Resolution

  1. Acknowledgment
    We will acknowledge receipt to your registered email address within five business days (excluding weekends and Japanese public holidays) of receiving your report.
  2. Review and verification
    Our responsible team will review your report and verify whether the vulnerability actually exists. We may ask you for additional information.
  3. Impact and severity assessment
    We will identify the affected products and versions, assess the severity with reference to metrics such as CVSS, and decide the priority of our response.
  4. Countermeasures
    We will prepare and provide the necessary countermeasures, such as software updates or workarounds.
  5. Reporting the results
    We will inform you of the results of our verification and the actions we have taken.

Status Updates Until Resolution

  • Progress updates to the reporter: Until our response is complete, we will update you on our progress by email approximately every 30 days. We will also contact you whenever there is a significant change.
  • Publication to customers: Once countermeasures are ready, we will publish the details, impact, and countermeasures on the security information page of the affected product (for example, EnergyGazer Security Information).
  • Coordination with other organizations: Where necessary, we will coordinate with organizations such as JPCERT/CC before publication.
  • Reporter’s name: We will not publish your name without your consent. If you would like to be acknowledged by name when we publish, please let us know in the form.

Handling of Personal Information

Any personal information you provide with your report will be used only to contact you, confirm details, and inform you of the results regarding your report, and will be managed in accordance with our Privacy Policy. Except as required by law, we will not provide it to any third party without your consent, including when we coordinate with other organizations.

Please Note

  • This policy does not promise any reward or bounty.
  • We do not promise to respond individually to every report or to resolve issues by a specific date.
  • We may change this policy without prior notice.

Established: October 9, 2026
Traffic Sim Co., Ltd.

Vulnerability Report Form

We accept reports through a dedicated form in our reception system. Click the button below to open the report form in a new tab.

The form is in Japanese only. You may fill it in in English.

Personal information entered in the form will be handled in accordance with “Handling of Personal Information” on this page and our Privacy Policy.

Copyright (c) TrafficSim Co., Ltd.