Information Security Policy
Information Security Policy
Effective Date: July 17, 2026
Introduction
GigaDevice Technology Group Inc. and its affiliates (hereinafter referred to as "GigaDevice" or "we") place a high priority on information security. This policy is intended to articulate to you (including customers, partners, suppliers, and website visitors) our management commitments, organizational framework, control measures, and practice standards regarding information security, so as to safeguard the confidentiality, integrity, and availability of all categories of information we collect, store, process, and transmit.
This policy applies to GigaDevice's global business processes, information systems, products and services, as well as all affiliates, employees, and third-party service providers collaborating with us. As a world-leading semiconductor solutions provider, GigaDevice has established an Information Security Management System (ISMS) compliant with ISO/IEC 27001:2022 and has obtained internationally recognized certifications including TISAX AL3 (the highest level), covering prototype protection, data protection, and high-risk threat defense capabilities. The Company is committed to the continuous enhancement of its information security system.
Information Security Management Organizational Structure
We have established a corporate security management organizational structure that integrates the Information Security Management System, the Trade Secret Management System, and the Product Cybersecurity Management System into a unified "Corporate Security" governance framework. This organizational structure comprises three tiers—"Decision-Making Layer — Management Layer — Execution Layer"—to ensure the effective formulation and implementation of information security strategies:
Decision-Making Layer (Corporate Security Committee): Chaired by the CEO of the Company, who serves as the Chief Security Officer, with senior management from each first-level department serving as committee members. This layer is responsible for formulating the Company's corporate security strategy, policies, and objectives; making decisions on key corporate security matters, approving major issues and critical protection measures, and allocating resource support; and ensuring the standardization, consistency, and continuous improvement of the Information Security Management System, the Trade Secret Management System, and the Product Cybersecurity Management System.
Management Layer (Corporate Security Management Group): Comprising senior management from each first-level department or their authorized representatives. This layer is responsible for implementing the resolutions of the Corporate Security Committee and bearing ultimate responsibility for corporate security within their respective departments; approving departmental information security management specifications; conducting regular departmental security inspections, tracking rectification of potential risks, and handling security breaches; and designating dedicated or part-time officers within departments responsible for information security, trade secrets, and product cybersecurity.
Execution Layer (Corporate Security Execution Group): Comprising three specialized execution sub-groups (Information Security Execution Sub-group, Trade Secret Execution Sub-group, and Product Cybersecurity Execution Sub-group). This policy focuses on the responsibilities of the Information Security Execution Sub-group: coordinated by the Information Security Management System lead from the Information Technology Department, with cooperation from information security officers designated by each department. This layer is responsible for assessing the threats and risk levels facing the Company's information security and coordinating the implementation of remedial measures; supervising the implementation of information security standards across all departments; and regularly reporting to the Corporate Security Committee on system operation and rectification progress.
Information Security Management Policy
GigaDevice adheres to the information security policy of "All-Employee Participation, Tiered Protection, Proactive Prevention, and Continuous Improvement":
All-Employee Participation: Embedding information security responsibilities into the job duties of every employee, enhancing company-wide security awareness through systematic training, and clarifying obligations for information reporting and risk prevention.
Tiered Protection: Implementing differentiated security controls based on the sensitivity of data and business impact, with a focus on protecting core information assets and customer privacy data.
Proactive Prevention: Emphasizing prevention as the primary approach, supplemented by real-time monitoring and post-incident response, and proactively identifying and mitigating risks through threat intelligence, risk assessments, and vulnerability management.
Continuous Improvement: Regularly reviewing the effectiveness of security policies and dynamically optimizing security controls in line with technological advancements and business changes, to ensure the suitability and advancement of the management system.
Information Security Management Measures
Organizational and Personnel Security
Background Checks: Conducting necessary verification of identity, educational qualifications, and professional credentials for candidates prior to employment.
Segregation of Duties and Least Privilege: Assigning system access rights in accordance with the "least privilege" principle, ensuring that employees can access only the information and resources necessary for their job responsibilities.
Confidentiality Agreements: Requiring all employees and third-party partners to sign confidentiality/non-disclosure agreements, clearly defining obligations for information security protection.
Offboarding Management: Promptly freezing or revoking system access rights and recovering company information assets upon employee resignation or position change.
Information Asset Management
Asset Inventory and Classification: Establishing and maintaining an inventory of information assets, and identifying and protecting information assets in accordance with the data classification and grading system.
Information Labeling and Transmission: Clearly labeling sensitive information and employing security measures such as encryption during information transmission to prevent unauthorized access or disclosure.
Access Control
Identity Authentication and Permission Management: Implementing role-based access control (RBAC) and employing strong password policies and multi-factor authentication (MFA) to protect critical systems.
Privileged Access Management: Strictly restricting and monitoring the use of privileged accounts, and logging all sensitive operational activities.
Physical and Environmental Security: Delineating secure areas and deploying electronic access control, video surveillance, and other facilities to prevent unauthorized personnel from entering sensitive areas such as server rooms, R&D workspaces, and laboratories.
Technical Security Controls
Network Security: Deploying firewalls, intrusion prevention systems (IPS), network isolation, and zoning controls, and conducting continuous monitoring of network traffic.
Endpoint Security: Implementing antivirus, data loss prevention (DLP), network access control, and software management on office and production endpoints to ensure device security and compliance.
Application and System Security: Following the Secure Software Development Lifecycle (SDLC) for internal system and product development processes, and conducting security reviews and vulnerability testing on code.
Data Security and Backup: Encrypting and backing up critical data, and conducting regular recovery testing to ensure business continuity and the integrity and security of data.
Vulnerability and Patch Management: Conducting regular technical vulnerability scans and risk assessments, promptly remediating high-risk vulnerabilities, and dynamically adjusting protection strategies by tracking threat intelligence.
Supply Chain and Third-Party Security
Supplier Risk Assessment: Assessing the information security capabilities of suppliers, distributors, and service providers prior to collaboration, and clearly defining their security responsibilities through contractual provisions.
Service Monitoring and Review: Regularly reviewing the security practices and deliverables of third-party service providers to ensure compliance with the Company's information security standards.
Cloud Service Security: Conducting specialized security assessments for cloud service usage scenarios to ensure that data storage and processing comply with regulatory requirements.
Information Security Incident Management
Incident Monitoring and Reporting: Establishing an information security incident monitoring system and defining employee incident reporting procedures to ensure that security incidents are detected and reported in a timely manner.
Emergency Response and Drills: Developing emergency response plans, establishing a Product Security Incident Response Team (GD PSIRT), and conducting regular emergency drills to effectively contain incident impact and restore system operations as soon as possible.
Incident Learning and Improvement: Drawing lessons from security incidents, analyzing root causes, and continuously optimizing protection strategies.
Business Continuity Management
Redundancy and Disaster Recovery: Implementing redundant deployment for critical information systems and infrastructure to eliminate single points of failure and ensure availability.
Business Continuity Planning: Developing and maintaining business continuity plans, and regularly testing and updating them to ensure that core business operations can continue during major failures or disaster scenarios.
Personal Information Protection
For details on how GigaDevice collects, uses, stores, shares, and protects your personal information, please refer to our separately published Privacy and Protection Policy. That policy provides detailed information on the rights you are entitled to (including the right to be informed, the right of access and data portability, the right to rectification, the right to erasure, the right to withdraw consent, and the right to data portability) and how to contact us to exercise these rights.
Compliance and Audit
Laws and Regulations Compliance: We strictly comply with applicable laws and regulations, including the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, and the EU General Data Protection Regulation (GDPR).
International Standards Certification: GigaDevice has obtained ISO/SAE 21434 certification for vehicle cybersecurity and TISAX AL3 certification, and continuously maintains the validity of these certifications.
Internal and External Audits: Conducting regular internal information security audits and cooperating with external third-party organizations for independent assessments, to verify the effectiveness and compliance of security controls.
Employee Training and Security Awareness
We organize information security training for all employees at least once a year, and conduct security awareness campaigns, phishing simulation exercises, and other activities on an ongoing basis, to continuously strengthen employees' security awareness and operational skills.
Policy Updates and Communication
This policy will be revised as necessary in response to changes in laws and regulations, the evolution of industry standards, and the Company's business development needs, with the effective date clearly indicated. We encourage you to review this policy periodically to stay informed of the latest content.
Contact Us
Should you have any questions or suggestions regarding this policy, or need to report information security incidents or exercise rights related to personal information, please contact us through the following channel: Email: security@gigadevice.com.
Supplementary Provisions
This policy takes effect from the date of issuance and shall remain in force until superseded by a new policy.
In the event of any conflict between this policy and national laws or regulations during implementation, national laws and regulations shall prevail.