Security policy.

BioLogic takes the security of its products, services, and infrastructure seriously. We appreciate reports from security researchers, customers, partners, and other third parties who help us identify and resolve potential vulnerabilities responsibly.

This page describes how to report a suspected security vulnerability affecting BioLogic products and how we handle such reports.

Last reviewed on 08 September 2026  ·  Cybersecurity Advisories

Reporting a security vulnerability

If you believe you have discovered a security vulnerability in a BioLogic product, firmware, software component, documentation package, or online service, please contact us at:

    Information to include

    Please include as much information as possible to help us understand, reproduce, and assess the issue. Useful information includes:

    • Affected product name and product ID
    • Firmware, software, or hardware version
    • Serial number or device variant, if relevant
    • Description of the vulnerability
    • Steps to reproduce the issue
    • Proof-of-concept code, logs, screenshots, or packet captures, if available
    • Potential impact
    • Whether the issue is already publicly known
    • Your contact details for follow-up questions

    Please do not include sensitive customer data, personal data, passwords, private keys, or confidential third-party information unless strictly necessary.

    Scope

    This policy applies to security vulnerabilities affecting BioLogic products and related digital assets, including but not limited to:

    • Instruments and electronic control products
    • Firmware and bootloader components
    • Configuration tools and related software
    • Product documentation where security-relevant information is affected
    • Public BioLogic web services

    This policy does not cover general technical support requests, feature requests, product availability questions, or non-security-related bugs. For those topics, please use the regular contact channels on our website.

    Coordinated vulnerability disclosure

    We follow a coordinated vulnerability disclosure process. After receiving a report, we will review the information, validate the issue, assess the potential impact, and determine appropriate remediation or mitigation steps.

    We ask reporters to give us reasonable time to investigate and resolve the issue before making information public. We also ask that you avoid actions that could harm BioLogic, our customers, or third parties, including:

    • Accessing, modifying, or deleting data that does not belong to you
    • Disrupting services or production systems
    • Performing denial-of-service testing
    • Using social engineering, phishing, or physical attacks
    • Publicly disclosing vulnerability details before coordination is complete

    What you can expect from us

    When you report a vulnerability to BioLogic, we aim to:

    • Acknowledge receipt of your report within a reasonable time
    • Keep you informed about the status of our analysis where appropriate
    • Work with you to understand and reproduce the issue
    • Assess affected products, versions, and configurations
    • Provide remediation, mitigation, or workaround information where applicable
    • Coordinate public disclosure when necessary
    • Credit you for the report if you request it and if legally and practically possible

    Response and remediation timelines depend on the complexity of the issue, affected products, safety considerations, customer impact, supply chain dependencies, and regulatory requirements.

    Security advisories

    When a vulnerability affects BioLogic products and requires customer action, we may publish a security advisory. Security advisories may include:

    • Affected product names and product IDs
    • Affected firmware or software versions
    • Vulnerability description
    • Severity rating, such as CVSS where applicable
    • Remediation, mitigation, or workaround information
    • References to CVE identifiers, if assigned
    • Revision history

    Product updates and remediation

    Depending on the affected product and vulnerability, remediation may include one or more of the following:

    • Firmware update
    • Software update
    • Configuration change
    • Network segmentation recommendation
    • Operational mitigation
    • Product-specific workaround
    • Customer notification or security advisory

    Customers are responsible for evaluating and applying updates or mitigations in their own operational environment. For laboratory and embedded environments, updates should be tested and deployed according to the customer’s safety, availability, and maintenance requirements.

    Vulnerability handling and communication

    BioLogic may coordinate vulnerability handling with customers, suppliers, CERTs, CVE Numbering Authorities, industry partners, or regulatory bodies where appropriate.

    If a vulnerability involves third-party components, open-source software, or supplier-provided technology, we may coordinate with the responsible party before publishing final information.

    No warranty

    Information provided under this security policy, including advisories, mitigations, and recommendations, is provided in good faith and for informational purposes. It does not create any additional warranty, guarantee, or contractual obligation beyond the applicable product agreements and statutory requirements.

    Contact

    For security vulnerability reports, please use the reporting form at the top of this page.

    BioLogic SAS

    www.biologic.net

    Non-security inquiries

    For non-security inquiries, please use the general contact options provided on our website, or contact BioLogic Support.

    To see published advisories for BioLogic instruments and software, go to Cybersecurity Advisories..