Report a Vulnerability
Our Commitment
Quantum Design and its businesses are committed to the safety and security of our products and customer data. We accept good faith, responsible reporting of potential security vulnerabilities in any of our products. If you believe you have found a security vulnerability in a Quantum Design product, please tell us.
How to Report
| security@qd-global.com | |
| Web Form | Click Here |
| Telephone | +1 858-481-4400 - ask for Product Security |
| Postal Address | 10307 Pacific Center Court San Diego, CA 92121 USA |
A useful report does not have to be a polished write-up. Please include as much of the following as you have:
- The product and, if you know it, the model and software or firmware version.
- What the problem is and what an attacker could do with it.
- Enough detail for us to reproduce it – steps, configuration, and any proof-of-concept code.
- Whether you believe the vulnerability is already being exploited or is publicly known.
- Whether and how you plan to publish.
- How best to reach you.
Reporting Guidelines
- Quantum Design employees and employees of our businesses should report issues or vulnerabilities through their normal business reporting channels.
- If you have instrument issues, service issues, software bugs, or general technical questions, please contact Customer Service or the Applications Team. If you would like to speak with a sales representative, please contact your local Quantum Design office.
- Do not engage in harmful or unlawful activity, threats, or extortion attempts.
- Do not take any action that could compromise the safety of people, laboratory equipment, cryogenic systems, or data with the goal of understanding or characterizing the vulnerability.
Scope
This policy covers Quantum Design products and the products of its businesses with digital elements: our instruments and the embedded software they contain, the control and analysis software we distribute with them, and the associated services we operate. See QDpart number for a list of compliant products.
The following are outside this policy, though we would still like to know:
- Vulnerabilities in third-party components we integrate.
- Our corporate websites and IT systems, unless the finding also affects a product.
What You Can Expect From Us
| Stage | Our Committment |
|---|---|
| Acknowledgement | We will confirm receipt of report within 3 business days. |
| Initial Assessment | We tell you whether we can reproduce the issue, and our initial view of its severity, within 10 business days. |
| Progress Updates | At least every 30 days until the report is closed, and whenever something material changes. |
| Remediation | We aim to have a fix or documented mitigation available within 90 days of confirming the vulnerability. Where an instrument requires a field service visit or a validated software release, this can take longer, and we will tell you why and when. |
| Advisory | Once a security update is available, we publish an advisory describing the vulnerability, the affected products and versions, the impact and severity, and what users should do. |
| Credit | There is no monetary reward or recognition program associated with reporting a vulnerability to Quantum Design. Quantum Design does not operate a bug bounty program. |
Please note: If a report turns out not to be a vulnerability, we will tell you that and explain our reasoning rather than simply closing it.
