Product Security
What is Product Security and Why Does it Matter?
Product security helps ensure that products are designed, built, and maintained - including, where applicable, products with digital elements - to be resilient against cyber threats throughout their entire lifecycle. It encompasses proactive, risk-based measures such as secure design, continuous risk assessment, vulnerability handling, security updates, and timely response to vulnerabilities.
In an increasingly connected world—especially in domains where products interact with sensitive systems, data, or patient care—product security is essential. It protects users, safeguards critical operations, and helps maintain trust by preventing unauthorized access, data breaches, and system disruptions. Strong product security is therefore not only a technical necessity but a fundamental requirement for safety, reliability, and supports our efforts to address evolving regulatory requirements, such as requirements that may apply to products with digital elements under the EU Cyber Resilience Act (CRA), where applicable.
Product security is a key discipline within the broader field of cybersecurity. While cybersecurity focuses on protecting systems, networks, and data during operation, product security ensures that products are secure by design and resilient from the outset maintained through lifecycle processes. Robust product security therefore provides the foundation for effective cybersecurity throughout the product lifecycle.
Our Commitment to Product Security
EVIDENT takes product security very seriously. Protecting the safety of our customers and patients, as well as the security and integrity of their systems and data, is among our highest priorities.
Security is an integral part of how we design, develop, and maintain our products. We continuously invest in processes, technologies, and expertise to anticipate threats, reduce risks, and respond effectively to emerging vulnerabilities. Our commitment includes maintaining a secure development lifecycle and, where applicable, supporting cybersecurity requirements for products with digital elements. We strive to build and operate products that our customers can trust with confidence.
Our Product Security Strategy at EVIDENT
Our product security strategy is built on a set of well-established and continuously evolving pillars that guide all phases of the product lifecycle:
- Risk and Threat Management
- We perform systematic threat modeling, risk assessment, and risk management to identify, evaluate, and mitigate potential security risks early and on an ongoing basis.
- Secure Development Practices
- Security is embedded into our development lifecycle through secure design principles, secure coding practices, and rigorous verification activities aligned with a secure development lifecycle (SDLC).
- Vulnerability and Patch Management
- We actively monitor, assess, prioritize, and address vulnerabilities in a risk-based manner, providing updates, patches, mitigations, or other guidance as appropriate to maintain product security throughout the supported product lifecycle.
- Coordinated Vulnerability Disclosure (CVD)
- We support coordinated vulnerability disclosure and collaborate with customers, researchers, and other external stakeholders to receive, assess, and address reported product vulnerabilities in a transparent, structured, and risk-based manner.
Together, these pillars ensure that security is not an afterthought but a continuous, integrated process across all our products.
Communication and Resources
EVIDENT provides dedicated communication channels for external product security inquiries, vulnerability reports, and product security incident reports so that submissions can be handled efficiently, securely, and by the appropriate experts.
Report a Product Security Vulnerability or Incident
If you are a customer, researcher, partner, or other external party and have identified a potential vulnerability in an EVIDENT product, or if you want to report a product security incident related to an EVIDENT product, please use the dedicated product security reporting channel below. This channel is intended for public intake of product-related vulnerability and incident reports and helps ensure that your submission is triaged by our dedicated product security team through a single point of contact (SPOC). EVIDENT does not intend to initiate legal action against security researchers who report vulnerabilities in compliance with applicable laws, in good faith, without accessing or affecting data, systems, or users without authorization, and in accordance with our Coordinated Vulnerability Disclosure (CVD) Policy.
To help us assess your report efficiently, please include concise but useful details, such as: (1) your name and contact information, unless you prefer to report anonymously; (2) the affected product, model, software/firmware version, and configuration; (3) a clear description of the vulnerability or incident and potential impact; (4) reproducible steps, proof-of-concept information, logs, screenshots, or other supporting evidence where available; and (5) whether the issue is actively being exploited or has been publicly disclosed. Please avoid including personal data, confidential customer data, patient data, credentials, or other sensitive information unless it is necessary to understand the report, and do not include data that you are not authorized to share. Any personal data you provide in connection with a report will be processed in accordance with our Privacy Policy.
For additional guidance, please download our Coordinated Vulnerability Disclosure (CVD) document here: Coordinated Vulnerability Disclosure (CVD) policy. The CVD document explains how EVIDENT receives, validates, coordinates, and communicates about vulnerability reports. EVIDENT will use reasonable efforts to acknowledge, assess, and address reports in a risk-based manner, but does not commit to fixed remediation deadlines unless separately stated in an official product security communication.
Product security reporting contact:
Email: product.security.reporting@evidentscientific.com
Phone : +44 20 4640 4917
Information on Security Updates and Addressed Vulnerabilities
Information on security updates and the vulnerabilities that they address can be found in our download section for the respective product: https://evidentscientific.com/en/downloads
Good-faith reporting and safe testing: EVIDENT values good-faith security research conducted in a lawful, non-disruptive manner. Please do not access, modify, destroy, exfiltrate, or disclose data that does not belong to you; do not degrade, interrupt, or attempt to gain unauthorized access to EVIDENT products, systems, services, or customer environments; do not perform testing that could affect patient safety, customer operations, or third-party systems; coordinate with EVIDENT before any public disclosure; and comply with applicable laws and the CVD document. EVIDENT does not authorize unlawful activity, unauthorized access, privacy violations, or testing that could harm users, products, systems, or data.
Important CRA note: This public reporting channel is for external product security vulnerability and incident intake. It does not replace, limit, or define separate obligations of EVIDENT under the EU Cyber Resilience Act or other applicable laws to notify market surveillance authorities, CSIRTs, ENISA, or other competent authorities, as applicable.
Disclaimer: The information on this page is provided for general informational purposes only and does not constitute a warranty, guarantee, or contractual commitment of any kind. No product can be guaranteed to be fully secure. References to security processes, vulnerability handling, security updates, mitigations, support periods, coordinated vulnerability disclosure, or applicable regulatory requirements are descriptive and do not create fixed remediation timelines or other obligations unless expressly agreed in applicable product documentation or contractual terms. The applicable product documentation and contractual terms govern the rights and obligations relating to our products and prevail over the information presented here. Statements regarding future developments, including regulatory compliance, are subject to change without notice.