At JTI, we are committed to delivering secure, reliable, and high‑quality products and services. This includes protecting our connected products, digital platforms, and consumers through security‑by‑design and continuous monitoring.
Our Coordinated Vulnerability Disclosure Policy reflects this commitment. We value feedback from our consumers and the cybersecurity community, and we encourage the responsible reporting of potential vulnerabilities.
Reporting scope
You can report vulnerabilities affecting JTI’s:
Heated tobacco device firmware, update mechanisms, and connectivity interfaces (for example Bluetooth)
Heated tobacco device companion mobile applications (including pairing, authentication and account management)
Selected external‑facing heated tobacco device cloud services and APIs (where explicitly permitted and monitored)
Out of scope for reporting
Customer support or product quality issues (handled via complaints channels)
Corporate IT systems not publicly exposed
General inquiries unrelated to security vulnerabilities
Safe harbor
JTI will not pursue legal action against individuals performing Good‑Faith Security Research, provided they:
Stay within defined scope
Avoid disruption or harm
Access only the minimum data necessary
Immediately stop if personal or sensitive data is encountered
Do not retain, share or misuse any data
Report vulnerabilities promptly and cooperate with JTI
Do not request compensation (except under any bug bounty or similar vulnerability reward program expressly offered by JTI)
Do not attempt extortion
Do not publicly disclose findings before coordination
Safe harbor does not apply to bad faith activities, out-of-scope systems or third‑party environments not controlled by JTI.
Reporting a vulnerability
If you believe you have identified a potential security vulnerability in a product or service that is in scope of this policy, please report it directly to us by clicking onto the link below:
You may also report a vulnerability indirectly via the relevant national CSIRT designated as coordinator.
Our goal is to receive, assess, coordinate, and remediate reported vulnerabilities in a controlled manner so that vulnerabilities can be diagnosed and addressed promptly before detailed information is disclosed more widely.
Security researchers are encouraged to protect sensitive technical vulnerability information during transmission. If PGP encryption is supported, the appropriate public key and instructions will be provided on this page.
Our Vulnerability Handling process
JTI manages vulnerabilities through a structured process for handling reported vulnerabilities, including assessment, diagnosis, and remediation. The process includes the following steps:
Acknowledgement of receipt of the report.
Assignment of a tracking reference and point of contact, where appropriate.
Assessment of the reported issue, including its severity and exploitability.
Detailed risk assessments where required.
Coordination with relevant product, engineering, and security teams.
Provision of status updates to the reporter, as appropriate, if they have indicated a willingness to receive them.
Remediation and release of fixes or other mitigating measures, where appropriate.
JTI aims to address validated vulnerabilities without undue delay. Where a reported vulnerability is validated and remediated, and a security update is made available, JTI may share and publicly disclose information about the fixed vulnerability and related information. Such disclosure may be delayed in duly justified cases if early publication would create greater security risk until users have had the possibility to apply the relevant patch, as further described in this policy.
If a vulnerability involves a third-party component, we may coordinate disclosure with the relevant vendor, as appropriate.
Disclosure and Security Communications
To minimize security risk:
You must not publicly disclose the vulnerability before coordination with JTI.
Disclosure timelines must be agreed.
JTI may take the following actions:
Notify affected users of a vulnerability and any relevant risk-mitigation or corrective measures they can take.
Publish security advisories, including:
Description of the vulnerability
Vulnerability identifier (if applicable)
Affected products
Impact and severity of the vulnerability
Remediation guidance, including any relevant security update information
Security updates and lifecycle
JTI will define and publish:
The applicable security support period for connected products in accordance with applicable legal requirements
Update delivery mechanisms (for example application updates) where applicable
User guidance on applying security fixes
Important rules
Do not test systems in ways that may disrupt operations
Limit testing strictly to validation needs
Ensure systems remain stable after testing
Testing of backend/cloud environments is limited to controlled conditions and must strictly follow this policy. Unauthorized testing of non-public or insufficiently monitored systems is prohibited.
Data protection
No personal information is required to submit a vulnerability report. Reports may be submitted anonymously. In the event that you choose to provide your personal information when you submit a report to us, please read our Privacy Policy for information on how we use your personal data.
Legal notice
Vulnerability reports may contain sensitive information.
JTI will:
Use the information solely to investigate, remediate, and improve security
Handle non-public vulnerability information according to confidentiality and security controls
Ensure that submission does not create any contractual obligation