Security Vulnerability Reporting Form
Product Security Vulnerability Reporting
If you identify a potential security vulnerability in a TDK product, including products of TDK Group companies, please report it through our Product Security Vulnerability Reporting Channel. TDK’s Product Security Incident Response Team (TDK PSIRT) reviews all submitted reports and coordinates appropriate investigation and response activities.
Please read the “Vulnerability Information Coordination Policy / Vulnerability Information Disclosure Policy” and the following “Handling of Personal Information in Connection with Vulnerability Reports for TDK Products.” Proceed only if you agree to their terms.
Handling of Personal Information in TDK Product Vulnerability Reports
TDK Corporation ("TDK") appropriately handles the name, company name, email address, telephone number, and other information entered in this form (collectively, "Personal Information") in accordance with the TDK Privacy Policy and the provisions set forth below.
1Reporting Vulnerabilities in TDK Products
1. Important Notes Regarding Vulnerability Reports
To ensure a smooth response process, please be aware of the following:
- Required Information: Please complete all required fields to facilitate prompt review and response.
- Specific Details: Please provide as much detail as possible, including reproduction steps, versions of target product, and any other relevant information.
- Methods of Contact: In addition to email correspondence, we may contact you by telephone to clarify the details of your report.
- Response Time: Investigation and analysis may take time. Reports received on weekends, public holidays, year-end/New Year holidays, summer vacations, or other company holidays will be handled on the next business day or later.
- Copyright of Responses: Please do not forward, and secondarily use (including, without limitation, posting on social media) all or part of TDK's responses without prior TDK’s permission.
2. Bug Bounty Program
TDK Group does not currently operate a bug bounty program (vulnerability reward program). Therefore, no monetary compensation or other rewards will be provided for vulnerability reports.
3. Vulnerability Information Coordination Policy / Vulnerability Disclosure Policy
TDK PSIRT will handle reported vulnerabilities in accordance with the applicable Vulnerability Information Coordination Policy and Vulnerability Disclosure Policy.
2Handling of Personal Information
1. Company Information and Personal Information Protection Manager
Company Name: TDK Corporation
Personal Information Protection Manager: TDK Product Security Incident Response Team (TDK PSIRT)
2. Purpose of Use of Personal Information
The Personal Information provided by you will be used solely for the following purposes:
- Verifying and responding to reported vulnerabilities;
- Recording and managing response activities and status.
3. Provision of Personal Information to Third Parties
When reviewing and responding to your report, TDK may determine that handling your report through one of TDK affiliated companies is more appropriate. In such cases, the Personal Information you provided, together with the contents of your report, may be shared with TDK affiliated companies (https://www.tdk.com/en/worldwide/index.html).
4. Outsourcing of Personal Information Processing
TDK may outsource all or part of the processing of Personal Information to external service providers to the extent necessary to achieve the purposes stated above. TDK and such subcontractors may also retain inquiry records and communication histories.
5. Inquiries Regarding Personal Information
If you wish to request inquiry to, correction of, deletion of your Personal Information, or suspension of the transfer of your Personal Information to TDK affiliated companies, please contact:
TDK Corporation
TDK Product Security Incident Response Team (TDK PSIRT)
2-5-1, Nihonbashi, Chuo-ku, Tokyo 103-6128, Japan
TDK_PSIRT@tdk.com
Continue to the Form