Vulnerability Disclosure Policy
NEXT. Inc. ("we/us") considers product security a critical responsibility and accepts reports of vulnerabilities in our products as follows.
1. Products in Scope
- NEXT-EMS Local Gateway (Model: NEXT-EMS-G1)
- Other products and services provided by us
2. How to Report
- E-mail: contact@next-g.co.jp
- Where possible, please include: product name, model, software version, description of the vulnerability, steps to reproduce, expected impact, and your contact details.
3. Our Process
- Acknowledgement: We will acknowledge receipt of your report within 5 business days.
- Triage & investigation: We assess validity, impact, and severity (e.g., CVSS v3).
- Remediation: We prioritize and provide fixes or mitigations in accordance with our security update policy.
4. Status Updates
- We will update the reporter on progress approximately every 30 days until resolution.
- When resolved, we will notify the reporter and inform affected customers of the impact and remediation through this page and our support channel.
5. Requests to Reporters
- Please do not disclose vulnerability details to third parties before a fix or mitigation is available.
- Please refrain from testing that may affect third-party systems or operating power-plant equipment.
6. Disclaimer
- This policy does not constitute a bug bounty program.
- This policy is subject to change without notice.
