JTI Coordinated Vulnerability Disclosure Policy

At JTI, we are committed to delivering secure, reliable, and high‑quality products and services. This includes protecting our connected products, digital platforms, and consumers through security‑by‑design and continuous monitoring.

Our Coordinated Vulnerability Disclosure Policy reflects this commitment.  We value feedback from our consumers and the cybersecurity community, and we encourage the responsible reporting of potential vulnerabilities.

Reporting scope

You can report vulnerabilities affecting JTI’s:

  • Heated tobacco device firmware, update mechanisms, and connectivity interfaces (for example Bluetooth)

  • Heated tobacco device companion mobile applications (including pairing, authentication and account management)

  • Selected external‑facing heated tobacco device cloud services and APIs (where explicitly permitted and monitored)

Out of scope for reporting

  • Customer support or product quality issues (handled via complaints channels)

  • Corporate IT systems not publicly exposed

  • General inquiries unrelated to security vulnerabilities

Safe harbor

JTI will not pursue legal action against individuals performing Good‑Faith Security Research, provided they:

  • Stay within defined scope

  • Avoid disruption or harm

  • Access only the minimum data necessary

  • Immediately stop if personal or sensitive data is encountered

  • Do not retain, share or misuse any data

  • Report vulnerabilities promptly and cooperate with JTI

  • Do not request compensation (except under any bug bounty or similar vulnerability reward program expressly offered by JTI)

  • Do not attempt extortion

  • Do not publicly disclose findings before coordination

    Safe harbor does not apply to bad faith activities, out-of-scope systems or third‑party environments not controlled by JTI.

Reporting a vulnerability

If you believe you have identified a potential security vulnerability in a product or service that is in scope of this policy, please report it directly to us by clicking onto the link below:

You may also report a vulnerability indirectly via the relevant national CSIRT designated as coordinator.

Our goal is to receive, assess, coordinate, and remediate reported vulnerabilities in a controlled manner so that vulnerabilities can be diagnosed and addressed promptly before detailed information is disclosed more widely.

Security researchers are encouraged to protect sensitive technical vulnerability information during transmission. If PGP encryption is supported, the appropriate public key and instructions will be provided on this page.

Our Vulnerability Handling process

JTI manages vulnerabilities through a structured process for handling reported vulnerabilities, including assessment, diagnosis, and remediation. The process includes the following steps: 

  • Acknowledgement of receipt of the report.

  • Assignment of a tracking reference and point of contact, where appropriate.

  • Assessment of the reported issue, including its severity and exploitability.

  • Detailed risk assessments where required.

  • Coordination with relevant product, engineering, and security teams.

  • Provision of status updates to the reporter, as appropriate, if they have indicated a willingness to receive them.

  • Remediation and release of fixes or other mitigating measures, where appropriate.

JTI aims to address validated vulnerabilities without undue delay. Where a reported vulnerability is validated and remediated, and a security update is made available, JTI may share and publicly disclose information about the fixed vulnerability and related information.  Such disclosure may be delayed in duly justified cases if early publication would create greater security risk until users have had the possibility to apply the relevant patch, as further described in this policy.

If a vulnerability involves a third-party component, we may coordinate disclosure with the relevant vendor, as appropriate.

Disclosure and Security Communications

To minimize security risk:

  • You must not publicly disclose the vulnerability before coordination with JTI.

  • Disclosure timelines must be agreed.

JTI may take the following actions:

  • Notify affected users of a vulnerability and any relevant risk-mitigation or corrective measures they can take.

  • Publish security advisories, including:

    • Description of the vulnerability

    • Vulnerability identifier (if applicable)

    • Affected products

    • Impact and severity of the vulnerability

    • Remediation guidance, including any relevant security update information

Security updates and lifecycle

JTI will define and publish:

  • The applicable security support period for connected products in accordance with applicable legal requirements

  • Update delivery mechanisms (for example application updates) where applicable

  • User guidance on applying security fixes

Important rules

  • Do not test systems in ways that may disrupt operations

  • Limit testing strictly to validation needs

  • Ensure systems remain stable after testing

  • Testing of backend/cloud environments is limited to controlled conditions and must strictly follow this policy. Unauthorized testing of non-public or insufficiently monitored systems is prohibited.

Data protection

No personal information is required to submit a vulnerability report. Reports may be submitted anonymously. In the event that you choose to provide your personal information when you submit a report to us, please read our Privacy Policy for information on how we use your personal data.

Legal notice

Vulnerability reports may contain sensitive information.

JTI will:

  • Use the information solely to investigate, remediate, and improve security

  • Handle non-public vulnerability information according to confidentiality and security controls

  • Ensure that submission does not create any contractual obligation