Komatsu cares deeply about maintaining the trust and confidence that our customers place in us. The security of our online platforms is of paramount importance.
We encourage security researchers that have discovered vulnerabilities in our services to disclose this to us in a responsible manner.
Komatsu will engage with security researchers when vulnerabilities are reported to us in accordance with this Responsible Disclosure Policy.
We will validate and fix vulnerabilities in accordance with our commitment to (information) security and privacy.
We will not take legal action against, or suspend or terminate the accounts of, researchers who discover and report security vulnerabilities in accordance with this Responsible Disclosure Policy.
Komatsu reserves all legal rights in the event of any non-compliance.
We encourage security researchers to share the details of suspected vulnerabilities with Komatsu’s Security Office by sending an email to securityoffice@komatsu.eu.
Komatsu will review the submission to determine if the finding is valid and has not been previously reported.
We ask security researchers to include detailed information along with reproducible steps for us to validate vulnerabilities.
If you identify a valid security vulnerability in compliance with this Responsible Disclosure Policy, Komatsu commits to:
Public disclosure of the submission details of any identified or alleged vulnerability without express written consent from Komatsu will deem the submission as noncompliant with this Responsible Disclosure Policy.
Don’t disclose the vulnerability until we have been able to correct it.
Don’t exploit any vulnerability by unnecessarily copying, deleting, adapting or viewing data. Or, for example, by downloading more data than is necessary to demonstrate vulnerability.
Don’t perform attacks such as breaching physical security, social engineering, distributed denial of service, and spamming.
Immediately erase all data obtained through demonstrating the vulnerability as soon as it is reported to Komatsu.
Don’t perform actions that could have an impact on the proper functioning of the system, both in terms of availability and performance, but also in terms of confidentiality and integrity of the data.
Don’t apply the following actions:
Acts under this Responsible Disclosure Policy should be limited to conducting tests to identify potential vulnerabilities and sharing this information with Komatsu. If, after the vulnerability has been removed, you wish to publish information about the vulnerability, we ask you to notify us at least one month before publication, and to give us the opportunity to respond.
Identifying us in a publication is only possible after we have given our explicit approval to do so.
If you have complied with the above terms of the Responsible Disclosure Policy and have not committed any other breaches, we will not take any legal action against you.
If you have any questions, we encourage you to address them to securityoffice@komatsu.eu
In case of doubt about the applicability of this policy, please contact us first via this e-mail address
We reserve the right to change the content of this Policy at any time.
Any personal data submitted or processed in connection with a report under this Responsible Disclosure Policy will be processed in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (GDPR). Further information on how Komatsu processes personal data is available in our Privacy Notice, which can be found on our website (www.komatsu.eu).