Security policy.
BioLogic takes the security of its products, services, and infrastructure seriously. We appreciate reports from security researchers, customers, partners, and other third parties who help us identify and resolve potential vulnerabilities responsibly.
This page describes how to report a suspected security vulnerability affecting BioLogic products and how we handle such reports.
Last reviewed on 08 September 2026 · Cybersecurity Advisories
Reporting a security vulnerability
If you believe you have discovered a security vulnerability in a BioLogic product, firmware, software component, documentation package, or online service, please contact us at:
Information to include
Please include as much information as possible to help us understand, reproduce, and assess the issue. Useful information includes:
- Affected product name and product ID
- Firmware, software, or hardware version
- Serial number or device variant, if relevant
- Description of the vulnerability
- Steps to reproduce the issue
- Proof-of-concept code, logs, screenshots, or packet captures, if available
- Potential impact
- Whether the issue is already publicly known
- Your contact details for follow-up questions
Please do not include sensitive customer data, personal data, passwords, private keys, or confidential third-party information unless strictly necessary.
Scope
This policy applies to security vulnerabilities affecting BioLogic products and related digital assets, including but not limited to:
- Instruments and electronic control products
- Firmware and bootloader components
- Configuration tools and related software
- Product documentation where security-relevant information is affected
- Public BioLogic web services
This policy does not cover general technical support requests, feature requests, product availability questions, or non-security-related bugs. For those topics, please use the regular contact channels on our website.
Coordinated vulnerability disclosure
We follow a coordinated vulnerability disclosure process. After receiving a report, we will review the information, validate the issue, assess the potential impact, and determine appropriate remediation or mitigation steps.
We ask reporters to give us reasonable time to investigate and resolve the issue before making information public. We also ask that you avoid actions that could harm BioLogic, our customers, or third parties, including:
- Accessing, modifying, or deleting data that does not belong to you
- Disrupting services or production systems
- Performing denial-of-service testing
- Using social engineering, phishing, or physical attacks
- Publicly disclosing vulnerability details before coordination is complete
What you can expect from us
When you report a vulnerability to BioLogic, we aim to:
- Acknowledge receipt of your report within a reasonable time
- Keep you informed about the status of our analysis where appropriate
- Work with you to understand and reproduce the issue
- Assess affected products, versions, and configurations
- Provide remediation, mitigation, or workaround information where applicable
- Coordinate public disclosure when necessary
- Credit you for the report if you request it and if legally and practically possible
Response and remediation timelines depend on the complexity of the issue, affected products, safety considerations, customer impact, supply chain dependencies, and regulatory requirements.
Security advisories
When a vulnerability affects BioLogic products and requires customer action, we may publish a security advisory. Security advisories may include:
- Affected product names and product IDs
- Affected firmware or software versions
- Vulnerability description
- Severity rating, such as CVSS where applicable
- Remediation, mitigation, or workaround information
- References to CVE identifiers, if assigned
- Revision history
Product updates and remediation
Depending on the affected product and vulnerability, remediation may include one or more of the following:
- Firmware update
- Software update
- Configuration change
- Network segmentation recommendation
- Operational mitigation
- Product-specific workaround
- Customer notification or security advisory
Customers are responsible for evaluating and applying updates or mitigations in their own operational environment. For laboratory and embedded environments, updates should be tested and deployed according to the customer’s safety, availability, and maintenance requirements.
Vulnerability handling and communication
BioLogic may coordinate vulnerability handling with customers, suppliers, CERTs, CVE Numbering Authorities, industry partners, or regulatory bodies where appropriate.
If a vulnerability involves third-party components, open-source software, or supplier-provided technology, we may coordinate with the responsible party before publishing final information.
No warranty
Information provided under this security policy, including advisories, mitigations, and recommendations, is provided in good faith and for informational purposes. It does not create any additional warranty, guarantee, or contractual obligation beyond the applicable product agreements and statutory requirements.
Contact
For security vulnerability reports, please use the reporting form at the top of this page.
BioLogic SAS
Non-security inquiries
For non-security inquiries, please use the general contact options provided on our website, or contact BioLogic Support.
To see published advisories for BioLogic instruments and software, go to Cybersecurity Advisories..