Coordinated Vulnerability Disclosure Policy

How we receive, evaluate, remediate, and coordinate the public disclosure of security vulnerabilities in Ikegawa products and services.

  • Version 1.0

    Published 2026-09-17

  • Acknowledge within 3 business days

    Tracking reference assigned

  • Triage within 7 business days

    Resolution target 90 days

  • Coordinated disclosure

    Safe harbour for good-faith research

DOCUMENT Coordinated Vulnerability Disclosure Policy
VERSION 1.0
PUBLISHED 2026-09-17
CHANGED BY Shūtō Akira

1Introduction

Ikegawa ("we", "us") is committed to the security of our products and the people who rely on them. We welcome reports of potential security vulnerabilities from security researchers, customers and members of the public. This Coordinated Vulnerability Disclosure (CVD) policy explains what is in scope, how to report a vulnerability to us, how we will respond, and how we coordinate public disclosure.

2Scope

This policy applies to the following products and services: IP cameras (incl. PTZ, fisheye, thermal, explosion-proof, corrosion-proof, ANPR, panoramic), recorders (NVR/DVR/XVR), modules, VMS, and Ikegawa mobile/cloud applications and services.

Eligibility for remediation: products and services receive security fixes while they are within their defined support period. For example, a product is not eligible to receive remediation once it is beyond its published end-of-support date.

The following are out of scope (examples): third-party services we do not operate; findings that are already public; reports with no demonstrable security impact; volumetric denial-of-service testing; and social-engineering of our staff or customers.

3How to report a vulnerability

Please report potential vulnerabilities through one of the following channels:

We provide more than one channel so that reporters can choose a method that suits them, including by telephone where a written channel is not accessible.

4Secure and anonymous reporting

To protect sensitive vulnerability information while it is being exchanged:

We will still accept reports sent through less secure channels — please do not let the lack of encryption stop you from reporting.

5What to include in your report

To help us validate and fix the issue quickly, please include as much of the following as you can:

  • Product identification — the affected product or service name, the affected version(s), and the platform or environment (OS, hardware) where applicable.

  • Vulnerability description — what the issue is and where it exists, and its type or class (e.g., buffer overflow, SQL injection, improper authentication).

  • Impact — the potential impact if the issue is exploited (confidentiality, integrity or availability), and a severity assessment or CVSS score if you have one.

  • Reproduction steps — step-by-step instructions to reproduce the issue, and proof-of-concept code or technical evidence if available.

  • Discovery information — the date you found the issue and how (testing method, tool, or accidental finding).

  • Your contact information — your name or alias (you may remain anonymous) and a channel for follow-up.

  • Disclosure intent — whether you intend to publish your findings, and any date you are working toward.

6What you can expect from us

After you submit a report, we will:

  • acknowledge receipt within 3 business days and assign a tracking reference;

  • aim to triage and validate your report within 7 business days, and contact you if we need more information;

  • keep you informed of our progress at reasonable intervals;

  • aim to deliver a resolution within 90 days, depending on complexity and any third parties involved;

  • notify you when the vulnerability has been remediated, and may invite you to confirm that the fix resolves it.

7Coordinated disclosure

We follow a coordinated disclosure approach:

  • We ask that you give us a reasonable opportunity to remediate the issue before disclosing it publicly.

  • We will not publicly disclose details of a reported vulnerability before it has been addressed; any public disclosure will be coordinated and agreed between you and us.

  • Where appropriate we agree an embargo period. Embargo timelines can be adjusted case by case by mutual agreement, including where a coordinator or other vendors are involved.

  • When a fix is released, we publish a security advisory and, where appropriate, request a CVE identifier and submit the information to the EU Vulnerability Database (EUVD).

8Where to find our security advisories

When a vulnerability has been remediated, we publish a security advisory so that users can assess whether they are affected and how to update. You can find our advisories at:

To be notified of new advisories, you can subscribe via our security mailing list by contacting security@ikegawacctv.com.

9Confidentiality and recognition

We treat vulnerability reports as confidential. We will not share the personal information you provide with third parties without your explicit consent, except where required by law.

With your permission, we are happy to credit you for your discovery in our advisory or on our acknowledgements page. Let us know if you would prefer to remain anonymous.

10Safe harbour and good-faith research

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you.

Good-faith research means, among other things, that you:

  • only interact with systems or accounts you own or have explicit permission to test;

  • avoid privacy violations, destruction of data, and any degradation of our services (for example, no denial-of-service testing);

  • access only the minimum data necessary to demonstrate the issue, and do not store, share or use it;

  • give us a reasonable time to resolve the issue before any disclosure.

11Policy changes

We may update this policy from time to time. The current version and its publication date are shown in Document control above; material changes are recorded below.

VersionChanged byDateReason
1.0Shūtō Akira2026-09-17Initial version


Questions about this policy? Write to security@ikegawacctv.com or return to the Cybersecurity Center.

Report a Vulnerability