APR encourages the responsible reporting of security vulnerabilities affecting its AGE-R products and official AGE-R device mobile applications.

Report a Security Vulnerability
Vulnerability Disclosure
Policy
Introduction
APR Co., Ltd. (“APR”) is committed to protecting the security of its products and mobile applications.
We strive to integrate cybersecurity throughout the design, development, and maintenance of our products and applications while complying with applicable cybersecurity requirements.
This Coordinated Vulnerability Disclosure (CVD) Policy (“Policy”) provides security researchers, customers, partners, and other interested parties with guidance on how to report potential security vulnerabilities affecting APR products and mobile applications. APR welcomes vulnerability reports that may help improve the security of its products and services.
Nothing in this Policy constitutes a waiver of any rights or remedies available to APR, authorizes any activity that would otherwise be unauthorized or unlawful, or binds any third party or law enforcement authority. APR will review reported vulnerabilities and determine, based on its internal assessment, whether any investigation, remediation, disclosure, or other action is appropriate.
APR does not operate a bug bounty program and does not provide financial rewards or other compensation for vulnerability reports submitted under this Policy.
Scope
This Policy applies only to security vulnerabilities affecting APR's AGE-R products, firmware, software, official AGE-R device mobile applications, and related systems or services that are owned, developed, operated, or maintained by APR.
The following are within the scope of this Policy:
- AGE-R hardware products;
- official AGE-R device mobile applications for iOS and Android;
- firmware and software provided by APR for its AGE-R products; and
- APR-operated systems or services necessary for the operation of AGE-R products or official AGE-R device mobile applications.
The following are outside the scope of this Policy:
- standalone third-party products, applications, services, or open-source software that are not developed or maintained by APR;
- APR websites, corporate IT systems, or internal networks that are unrelated to the operation of AGE-R products or official AGE-R device mobile applications;
- general customer support, warranty, or repair requests;
- feature requests or product improvement suggestions; and
- issues unrelated to cybersecurity.
Reports concerning products or software that have reached the end of their support lifecycle may be reviewed at APR's discretion. Acceptance or review of such a report does not constitute a commitment by APR to provide a security update, remediation, or other support.
Security Research Guidelines
Any testing, research, and reporting activities must be conducted in accordance with applicable laws, regulations, contractual obligations, and third-party rights.
When conducting security research, please:
- do not access or attempt to access any product, system, account, service, or data unless you have obtained appropriate authorization from its owner;
- do not intentionally access, modify, copy, retain, or delete data that does not belong to you;
- do not submit personal information unrelated to the reported vulnerability or personal information of third parties unless such information is strictly necessary to demonstrate the vulnerability;
- do not retain, disclose, or distribute personal data or confidential information obtained during security research beyond what is reasonably necessary to verify and report the vulnerability;
- if you inadvertently access personal data or confidential information, stop the relevant activity immediately and notify APR without accessing or retaining any additional information;
- avoid disrupting APR products or services or adversely affecting other users;
- do not perform denial-of-service, destructive, brute-force, credential-stuffing, or other activities that may adversely affect the availability or integrity of APR products or services;
- do not introduce malware, establish persistent access, or create backdoors;
- do not use social engineering, phishing, spam, or physical attacks;
- do not conduct testing that may cause personal injury, unsafe device operation, electrical or thermal damage, battery damage, or other physical harm;
- do not alter device output, intensity, temperature, voltage, current, operating time, or safety controls in a manner that may create a safety risk;
- limit your activities to those reasonably necessary to verify and demonstrate the reported vulnerability; and
- do not request payment, employment, commercial opportunities, or other benefits as a condition for reporting or withholding disclosure of a vulnerability.
Items Not Considered Vulnerabilities
APR may determine that the following do not constitute valid security vulnerabilities under this Policy:
- reports based solely on automated tools or scans without meaningful verification;
- speculative or theoretical issues without sufficient evidence of practical exploitability or material impact;
- duplicate reports or vulnerabilities already known to APR;
- previously disclosed vulnerabilities for which an appropriate remediation or mitigation is available;
- vulnerabilities that cannot be reproduced or lack sufficient supporting information;
- issues affecting only third-party products or services not controlled or maintained by APR;
- open redirects, clickjacking, self-XSS, missing email-security records, or rate-limiting issues without demonstrated material impact;
- intended product functions that do not result in unauthorized access or another material cybersecurity impact; and
- issues requiring physical destruction, unsafe modification, or abnormal use of a product.
Reports falling within the above categories may be closed without further investigation, remediation, or individual notification.
If a reported issue concerns a third-party library, component, service, or vendor used in an APR product or application, APR may forward relevant information to the applicable supplier, developer, or maintainer and coordinate with that party as appropriate.
Coordinated Disclosure
We encourage you to report the vulnerability to APR before making any public disclosure.
To help protect our customers and users, we request that you do not publicly disclose or share vulnerability details with third parties until APR has completed an appropriate assessment and, where appropriate, remediate or mitigate the reported issue. APR may coordinate an appropriate disclosure timeline with the reporting party where necessary. Where appropriate, APR may publish information regarding confirmed vulnerabilities, available mitigations, or security updates through its security advisories or other appropriate channels.
Use of Reported Information
By submitting a report, you acknowledge that APR may use and share the information contained in the report to the extent reasonably necessary to:
- review, reproduce, assess, remediate, or mitigate the reported issue;
- improve the security of APR products and applications;
- coordinate with APR affiliates, service providers, suppliers, developers, or component maintainers; and
- comply with applicable legal or regulatory obligations.
Personal data submitted in connection with a vulnerability report will be processed in accordance with APR’s Privacy Notice available at [PRIVACY NOTICE].
Limitations
Submission of a report does not guarantee that the reported issue will be classified as a security vulnerability, that remediation or other corrective action will be implemented, or that an individual response or status update will be provided.
APR reserves the right to determine the validity, severity, priority, and appropriate response for all reported issues based on its internal assessment.
APR reserves the right to modify, suspend, or terminate this Policy at any time without prior notice.