Skip to content
  • Events
  • Blog
  • Events
  • Blog
Edinburgh Instruments
  • About Us
  • Products

    UV-Vis Spectrophotometers

    • DB30

    Fluorescence Spectrometer

    • FE30

    FTIR Spectrometers

    • IA30
    View All Products
  • Applications
  • Contact
  • About Us
  • All Products
    • DB30
    • FE30
    • IA30
  • Applications
  • Events
  • Blog
  • Distribution & Agents
  • Contact Us
Edinburgh Instruments

Coordinated Vulnerability disclosure document

Responsible reporting of potential product security vulnerabilities

Edinburgh Analytical is committed to maintaining the security of its products and welcomes reports of suspected cybersecurity vulnerabilities from customers, researchers, partners and other third parties. Responsible and coordinated disclosure helps protect users while reported issues are investigated, assessed, and, where necessary, remediated.

This policy applies to Edinburgh Instruments, Edinburgh Analytical and Edinburgh Sensors software, firmware, connected systems and supported product platforms.

Report a Vulnerability: CRAsecurity@edinst.com

How to Report

Please include, where possible:

  • Product name and version
  • Software or firmware version
  • Description and potential impact
  • Steps to reproduce the issue
  • Supporting evidence, screenshots or logs
  • Your contact details and disclosure preferences
 

Please do not publicly disclose vulnerability details until Edinburgh Analytical has had a reasonable opportunity to investigate and implement appropriate mitigations or corrections.

Good-faith research

We ask researchers to:

  • Avoid disrupting customer or company operations
  • Avoid accessing, changing, destroying or disclosing data
  • Test only systems you own or are authorised to assess
  • Limit testing to what is necessary to validate the finding
  • Maintain confidentiality during coordinated investigation and remediation
 

What you can expect from us

  • Acknowledgement of the report
  • Assessment and validation of the reported issue
  • Appropriate communication with the reporter
  • Risk-based mitigation or remediation action
  • Customer communication where necessary
  • Regulatory reporting where required by applicable law
 

Disclosure process

Confirmed vulnerabilities will be managed according to their technical risk, potential customer impact, and affected product versions. Edinburgh Analytical may issue security advisories, software or firmware updates, mitigations, technical bulletins or other communications as appropriate.
We will coordinate disclosure timing with the reporter where practical, while retaining the right to communicate earlier where required to protect customers, meet legal obligations or address active exploitation.

Legal notice

This policy does not grant permission to access, modify, interfere with or test systems that you do not own or have explicit authorisation to assess. Activities that could adversely affect Edinburgh Analytical, its customers or third parties must not be performed

Policy Owner: Product Security Lead

Last Updated: September 2026 

Keep up to date with the latest from Edinburgh Analytical

Join our mailing list and keep up with our latest videos, app notes and more!

LOCATION:
  • Edinburgh Instruments Ltd.
    2 Bain Square, Kirkton Campus, Livingston, EH54 7DQ
  • sales@edinst.com
  • +44 1506 425 300
ABOUT:
  • About Us
  • Blog
  • Events
  • Distribution & Agents
  • Contact Us
  • About Us
  • Blog
  • Events
  • Distribution & Agents
  • Contact Us
PRODUCTS:
  • UV-Vis Spectrophotometers
  • Fluorescence Spectrometer
  • FTIR Spectrometers
  • All Products
  • UV-Vis Spectrophotometers
  • Fluorescence Spectrometer
  • FTIR Spectrometers
  • All Products
LEGALS:
  • Privacy Policy
  • Terms and Conditions
  • Coordinated Vulnerability Disclosure Policy
  • Privacy Policy
  • Terms and Conditions
  • Coordinated Vulnerability Disclosure Policy
SOCIALS:
Youtube Linkedin Instagram Facebook
©2024 Edinburgh Instruments. Registered in England and Wales No: 962331. VAT No: GB 271 7379 37
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}