Coordinated Vulnerability Disclosure Policy

Responsible reporting of potential product security vulnerabilities

Edinburgh Sensors is committed to maintaining the security of its products and welcomes reports of suspected cybersecurity vulnerabilities from customers, researchers, partners and other third parties. Responsible and coordinated disclosure helps protect users while reported issues are investigated, assessed, and, where necessary, remediated.

This policy applies to Edinburgh Instruments, Edinburgh Analytical and Edinburgh Sensors software, firmware, connected systems and supported product platforms. 

Report a vulnerability: CRAsecurity@edinst.com

How to report

Please include, where possible:

  • Product name and version
  • Software or firmware version
  • Description and potential impact
  • Steps to reproduce the issue
  • Supporting evidence, screenshots or logs
  • Your contact details and disclosure preferences

Please do not publicly disclose vulnerability details until Edinburgh Instruments has had a reasonable opportunity to investigate and implement appropriate mitigations or corrections.

Good-faith research

We ask researchers to:

  • Avoid disrupting customer or company operations
  • Avoid accessing, changing, destroying or disclosing data
  • Test only systems you own or are authorised to assess
  • Limit testing to what is necessary to validate the finding
  • Maintain confidentiality during coordinated investigation and remediation

What you can expect from us

  • Acknowledgement of the report
  • Assessment and validation of the reported issue
  • Appropriate communication with the reporter
  • Risk-based mitigation or remediation action
  • Customer communication where necessary
  • Regulatory reporting where required by applicable law

Disclosure process

Confirmed vulnerabilities will be managed according to their technical risk, potential customer impact, and affected product versions. Edinburgh Instruments may issue security advisories, software or firmware updates, mitigations, technical bulletins or other communications as appropriate. We will coordinate disclosure timing with the reporter where practical, while retaining the right to communicate earlier where required to protect customers, meet legal obligations or address active exploitation.

Legal notice

This policy does not grant permission to access, modify, interfere with or test systems that you do not own or have explicit authorisation to assess. Activities that could adversely affect Edinburgh Instruments, its customers or third parties must not be performed.

Policy owner: Product Security Lead 

Last updated: September 2026