Retail Food Industry Logistics Hospitality Service & Cloud

DIGI Product Cybersecurity Policy

This policy applies to products and solutions provided under the DIGI brand.



1. Basic Policy (Commitment)

DIGI regards cybersecurity safety as a crucial part of product quality to provide safe and reliable products and solutions to all customers. We continuously maintain and improve product security levels to provide customers with safe and reliable products.

2. Organizational Measures and Product Security Response System

Under company-wide policy, we establish a system to ensure product security and formulate and operate appropriate regulations. In addition, if a cyberattack occurs that affects the provision of our products, we will work closely with our internal information systems department and related departments to minimize damage and achieve rapid recovery.

3. Compliance with Laws, Regulations, and International Standards

Our company complies with domestic and international laws and regulations related to cybersecurity. In particular, we are promoting the establishment of systems for compliance with international regulations such as the European Cyber Resilience Act (CRA) and industrial security standards such as IEC 62443, and we will review this policy and operational framework as needed in response to changes in the market environment. We also require cooperation across the entire supply chain, including suppliers and development partners, in enforcing appropriate security standards.

4. Secure Product Development (Secure by Design Product Lifecycle)

We properly manage product security risks throughout the entire product lifecycle (planning, design, development, manufacturing, shipping, maintenance, disposal). We practice development based on the principles of "Secure by Design," and identify, assess, and appropriately address known vulnerabilities before product release in accordance with their associated cybersecurity risks.

5. Appropriate Response to Product Vulnerabilities and Information Disclosure

We have established processes to continuously collect and manage vulnerability information related to our products and the software we use, enabling rapid response to discovered vulnerabilities. Furthermore, based on our vulnerability disclosure process, we strive to ensure appropriate information disclosure and sharing in collaboration with external organizations and stakeholders as necessary.

6. Handling updates and providing information to customers

Maintaining product security levels is achieved through a combination of our own measures and proper use by our customers. If vulnerabilities that could cause damage or performance impact are found in our products after shipment, we will promptly take appropriate measures such as updates or providing countermeasure software. At the same time, we will continue to provide warnings and security information to ensure customers can use our products safely.

7. Continuous Improvement and Employee Education

We continuously improve our internal systems and processes related to product security and strive to enhance the maturity of our organizational responses. We also continuously conduct education and training aimed at product development, quality assurance, and improving the security literacy of all related employees.


DIGI Vulnerability Disclosure Policy (CVD Policy)

This policy applies to products and services provided under the DIGI brand.



1. Introduction

DIGI accepts and responsibly responds to external vulnerability reports aiming to enhance the security of its own products and services. We take vulnerability information from external security researchers, customers, and partners seriously, and strive to provide safer products and solutions.

2. Organizational Structure and Scope of Application

Each DIGI group company establishes an appropriate product security response team to manage vulnerabilities and security incidents related to the products and services for which it is responsible.
These teams are responsible for receiving vulnerability reports and coordinating appropriate responses in cooperation with relevant departments.

3. Reporting Method

If you discover a vulnerability related to our products or services, please contact us via the dedicated email address we provide. For prompt analysis and response, please cooperate by providing the following information whenever possible when reporting
  • Reporter information: Name, company/organization name, department name, contact information (email address, etc.)
  • Vulnerability Overview: Explanation of the Issue and Under What Circumstances It Was Discovered
  • Reproduction Procedures and Technical Information: Steps for reproducing vulnerabilities, sample code, screenshots, etc.
  • Potential impact: Risks if the vulnerability is exploited, and the specific impact on customers and product performance


4. Post-Report Response Process

1. Verification and investigation: Based on the reported information, the responsible product security response team and relevant departments collaborate to verify the reproducibility of vulnerabilities and assess their impact. During the investigation process, we will share progress with reporters as much as possible and strive for high transparency.

2. Remediation response: If the existence of a vulnerability is confirmed, appropriate remediation measures (such as creating product updates, preparing configuration change procedures, developing workarounds, etc.) are taken promptly.



5. legal protection

We respect vulnerability reports made in good faith in accordance with this policy.
We will not pursue legal action against reporters who identify and report vulnerabilities in good faith and in accordance with this policy. If you intend to conduct security research beyond what is reasonably necessary to identify and report a vulnerability, please contact us in advance.

6. Update of this policy

This policy may be reviewed or revised as necessary in response to domestic and international cybersecurity regulations (such as the European Cyber Resilience Act (CRA)) and changes in market conditions. The latest policies are published on our website and updated information is reflected.

If you discover a security vulnerability in our products, please contact us via email at the address below.

eucompliance@jp.digi-group.com