Report a Vulnerability

Our Commitment

Quantum Design and its businesses are committed to the safety and security of our products and customer data. We accept good faith, responsible reporting of potential security vulnerabilities in any of our products. If you believe you have found a security vulnerability in a Quantum Design product, please tell us.

How to Report

Email security@qd-global.com
Web Form Click Here
Telephone +1 858-481-4400 - ask for Product Security
Postal Address 10307 Pacific Center Court
San Diego, CA 92121
USA

A useful report does not have to be a polished write-up. Please include as much of the following as you have:

  • The product and, if you know it, the model and software or firmware version.
  • What the problem is and what an attacker could do with it.
  • Enough detail for us to reproduce it – steps, configuration, and any proof-of-concept code.
  • Whether you believe the vulnerability is already being exploited or is publicly known.
  • Whether and how you plan to publish.
  • How best to reach you.

Reporting Guidelines

  • Quantum Design employees and employees of our businesses should report issues or vulnerabilities through their normal business reporting channels.
  • If you have instrument issues, service issues, software bugs, or general technical questions, please contact Customer Service or the Applications Team. If you would like to speak with a sales representative, please contact your local Quantum Design office.
  • Do not engage in harmful or unlawful activity, threats, or extortion attempts.
  • Do not take any action that could compromise the safety of people, laboratory equipment, cryogenic systems, or data with the goal of understanding or characterizing the vulnerability.

Scope

This policy covers Quantum Design products and the products of its businesses with digital elements: our instruments and the embedded software they contain, the control and analysis software we distribute with them, and the associated services we operate. See QDpart number for a list of compliant products.

The following are outside this policy, though we would still like to know:

  • Vulnerabilities in third-party components we integrate.
  • Our corporate websites and IT systems, unless the finding also affects a product.

What You Can Expect From Us

Stage Our Committment
Acknowledgement We will confirm receipt of report within 3 business days.
Initial Assessment We tell you whether we can reproduce the issue, and our initial view of its severity, within 10 business days.
Progress Updates At least every 30 days until the report is closed, and whenever something material changes.
Remediation We aim to have a fix or documented mitigation available within 90 days of confirming the vulnerability. Where an instrument requires a field service visit or a validated software release, this can take longer, and we will tell you why and when.
Advisory Once a security update is available, we publish an advisory describing the vulnerability, the affected products and versions, the impact and severity, and what users should do.
Credit There is no monetary reward or recognition program associated with reporting a vulnerability to Quantum Design. Quantum Design does not operate a bug bounty program.

Please note: If a report turns out not to be a vulnerability, we will tell you that and explain our reasoning rather than simply closing it.

Web Form

First Name
Please enter your first name.
Last Name
Please enter your last name.
Email
Please enter your email.
Describe the vulnerability:
(400 character limit)
Please describe the vulnerability (400 characters max).
How was the vulnerability discovered?
(400 character limit)
Please describe how the vulnerability was discovered (400 characters max).
Please acknowledge the Reporting Guidelines and the data use statement.
Please complete the reCAPTCHA.