Product Security
Our Approach to Product Security
As a provider of industrial equipment and control systems, SINFONIA TECHNOLOGY CO., LTD. (hereinafter “SINFONIA”) recognizes that cybersecurity risks inherent in products may affect product safety, reliability, and business continuity.
To help customers use our products and services with confidence, we work to ensure security throughout the product lifecycle, from planning and design through development, manufacturing, operation after shipment, and disposal.
Risk-Based Security Measures
We identify and assess cybersecurity risks by considering the intended use of each product, its anticipated operating environment, connectivity, and potential threats. Based on this assessment, we implement reasonable and appropriate security measures.
Security Throughout the Product Lifecycle
We consider product security throughout the entire product lifecycle:
Planning → Design → Development → Verification → Manufacturing → Inspection and Testing → Shipment → Operation → Disposal
Secure by Design
We treat security as an integral part of product development rather than as an add-on. Security considerations are incorporated into product design and development from the earliest stages.
Product Vulnerability Management
We continuously monitor vulnerability information relevant to our products. When a vulnerability is identified, we assess its potential impact, implement appropriate corrective or mitigating measures, and provide relevant information to customers as necessary.
Governance and Responsibilities
We clearly define roles and responsibilities for product security and address product security matters in a planned and coordinated manner through our Product Security Incident Response Team (PSIRT) and Computer Security Incident Response Team (CSIRT).
Compliance
Our officers, employees, and contractors comply with this policy and all related internal rules and procedures and work to maintain product security.
Response to Product Security Issues
If a product security issue arises from a vulnerability or other security weakness in a SINFONIA product, we promptly take appropriate measures to contain the impact and address the issue.
Continuous Improvement
We continuously review and improve this policy and our product security activities in response to changes in the threat landscape, technological developments, applicable laws and regulations, and customer requirements. We also provide ongoing education and awareness activities to strengthen product security awareness across our organization.
Product Security Organization
SINFONIA has established a Product Security Incident Response Team (PSIRT) to address vulnerabilities and security issues involving our products and services.
The Quality Management Department serves as the PSIRT secretariat. The PSIRT works with relevant functions, including business divisions,legal, and IT. Within each business division, engineering, quality assurance, procurement, and other functions associated with the affected product investigate potential impact and consider appropriate measures.
The PSIRT also shares information and coordinates response activities with SINFONIA’s internal Computer Security Incident Response Team (CSIRT).

Vulnerability Disclosure Policy
SINFONIA works with security researchers, customers, business partners, and other relevant parties to address vulnerabilities affecting our products and services, with the aim of preventing security incidents and minimizing potential impact.
Coordinated Vulnerability Disclosure
We coordinate with individuals and organizations that discover or report vulnerabilities. As a general rule, SINFONIA does not publicly disclose information about an unremediated vulnerability until a fix, mitigation, or workaround is available.
Protection for Good-Faith Reporting
SINFONIA will not subject a person who reports a vulnerability in good faith to adverse treatment, legal action, or retaliation in connection with the report.
Compliance with Legal and Contractual Requirements
We disclose vulnerability information at an appropriate time and in an appropriate manner, in accordance with applicable laws and regulations, including the EU Cyber Resilience Act where applicable, and our contractual obligations to customers.
Publication of Vulnerability Information
If we determine that a vulnerability may affect customers or other relevant parties, we publish information through our “Security Advisories”, together with available corrective measures, mitigations, or workarounds, as appropriate.
Report a Product Security Vulnerability
SINFONIA accepts reports of potential security vulnerabilities affecting our products and services. If you believe you have identified a security issue, please submit a report using the form below.
