Vulnerability Disclosure Policy

Introduction

Particle Measuring Systems is committed to providing secure products, software and services.Ā This policyĀ covers security research involving Particle Measuring Systems products with digital elements, including specificĀ firmware, software, and related services listed in the Scope section.Ā Ā As part of this commitment, we maintain a robust security program to identify and mitigate potential vulnerabilitiesĀ in our productsĀ within our product lifecycle support periods.Ā Ā  We will work with security researchers around the world who wish to help identify potential vulnerabilities in our firmware and software that were not already detected through our internal controls, thereby enabling us to address those appropriately.Ā 

Ā Our Vulnerability Disclosure Program (VDP) is a structured framework for security researchers to identify and submit security vulnerabilities to us. This policy describes what systems and types of research are covered under this policy, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities.Ā 

Ā 

Authorization

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Particle Measuring Systems will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.Ā 

Ā 

Guidelines

Under this policy, ā€œresearchā€ means activities in which you:Ā 

  • Notify us as soon as possible after you discover a real or potential security issue.Ā 
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.Ā 
  • Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.Ā 
  • Provide us at least 90 calendar days before public disclosure, unless we agree to a different coordinated disclosure timeline as some vulnerabilities may require longer remediation timelines.Ā 
  • Do not submit a high volume of low-quality reports.Ā 

Ā Once you’ve established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify usĀ promptlyĀ and securely, and not disclose this data to anyone else.Ā ItĀ is imperative that a solution be identified, and a coordinated disclosure be developed to minimize impact.Ā 

Ā The following test methods are not authorized:Ā 

  • Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or dataĀ 
  • Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testingĀ 

Scope

Ā This policy applies to all products with digital elements produced or distributed by Particle Measuring Systems, including firmware, software, and services.Ā  Any product that is not in scope are not authorized for testing.Ā 

Ā Any service not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any). If you aren’t sure whether a system is in scope or not, contact us atĀ psec@pmeasuring.com.Ā 

Ā Though we develop and maintain other internet-accessible systems or services, we ask that active research and testing only be conducted on the systems and services covered by the scope of this document. If there is a particular system not in scope that you think merits testing, please contact us to discuss it first. We may increase the scope of this policy over time.

Reporting a vulnerability

InformationĀ submittedĀ under this policy will be used for defensive purposes only – to mitigate or remediate vulnerabilities. If your findings include newly discovered vulnerabilities that affect all users of a product or service and not solely Particle Measuring Systems, we may share your report with theĀ appropriate agenciesĀ where it will be handled under their coordinated vulnerability disclosure process. We will not share your name or contact information without express permission.Ā Ā We will handleĀ submittedĀ reports and related personal dataĀ in accordance withĀ applicable confidentiality, privacy, and data-protection requirementsĀ 

Ā We ask you to only share details about the vulnerability you found or the affected products throughĀ secure channelsĀ that guarantee the confidentiality and the integrity of the conversations.Ā Ā 

Ā We strongly recommend encrypting your report using our PGP key. If you are unfamiliar or uncomfortable with PGP, send us a normal email without any info on the vulnerability you discovered so we can agree on an appropriate secure channel.Ā 

Do NOT send us information about active vulnerabilities that may affect our products through regular email.Ā 

 

Particle Measuring Systems PSEC <psec@pmeasuring.com>
Ā PGP Fingerprint:
5D73 8FED 992E 797C 084C 7349 24DA 3E8D 7B39 8EADĀ 

Ā Public Key:Ā 

Ā —–BEGIN PGP PUBLIC KEY BLOCK—–Ā 

mDMEalAK+hYJKwYBBAHaRw8BAQdAgsggb4MMXNQmRBoalNmYXkoMLoixJPN+M5gUĀ 

amUJgBi0NVBhcnRpY2xlIE1lYXN1cmluZyBTeXN0ZW1zIFBTRUMgPHBzZWNAcG1lĀ 

YXN1cmluZy5jb20+iLUEExYKAF0WIQRdc4/tmS55fAhMc0kk2j6NezmOrQUCalAKĀ 

+hsUgAAAAAAEAA5tYW51MiwyLjUrMS4xMiwyLDECGwMFCQWkwqYFCwkIBwICIgIGĀ 

FQoJCAsCBBYCAwECHgcCF4AACgkQJNo+jXs5jq0NjQD/Y/rf1HG3GC19TDX0D2RPĀ 

BNvR48klLO5On8kHwQt/rCoBANTq42c5Yp4iBcp7DPeNU63769B7uomTYesf3/nBĀ 

rr8AuDgEalAK+hIKKwYBBAGXVQEFAQEHQBpQuJp9p16d1wvcNocN8JK/iSNdLj+rĀ 

Gmmcd+zieIQdAwEIB4iaBBgWCgBCFiEEXXOP7ZkueXwITHNJJNo+jXs5jq0FAmpQĀ 

CvobFIAAAAAABAAObWFudTIsMi41KzEuMTIsMiwxAhsMBQkFpMKmAAoJECTaPo17Ā 

OY6toz0BAL/TXF4X48WmAHhxt7VJMBb6zGUBLdZtjV/yqG4xlGEQAP99e0wheJ8cĀ 

O1UD77jmKzwV4M8aPSpjAqDAJitNecGdCg==Ā 

=iGazĀ 

—–END PGP PUBLIC KEY BLOCK—–Ā 

Using PGP encryption helps ensure your communication remains confidential and protected during transmission.Ā 

Ā If you share contact information, we will acknowledge receipt of your report within 5 business days.Ā 

Ā What we would like to see from youĀ 

Ā To help us triage and prioritize submissions, we recommend that your reports:Ā 

  • Product name and versionĀ 
  • Description of the vulnerabilityĀ 
  • Steps to reproduce the issueĀ 
  • Potential impactĀ 
  • Any proof-of-concept or supporting materialsĀ 

Ā What you can expect from usĀ 

When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible.Ā 

  • We will acknowledge receipt of your report withinĀ 5 business daysĀ 
  • We will investigate and validate all reportsĀ promptlyĀ 
  • We will work to remediate confirmed vulnerabilities in a timely mannerĀ 
  • We may contact you for additional information during our investigationĀ 
  • We may, with your express consent, publicly recognize you or your organization for a valid vulnerability report after remediation or coordinated disclosure, subject to applicable law. Public recognition is optional and we may decline, delay, or modify public recognition where necessary for safety, legal, regulatory, confidentiality, sanctions, export-control, third-party, or operational reasonsĀ 

Reports may be submitted anonymously. If you do not provide contact information, we may be unable to acknowledge receipt, request clarification, coordinate remediation, or provide recognition, but we will review reports containing sufficient technical detail.Ā 

Ā Public recognition, if provided, is not compensation and does not create any entitlement to payment, employment, vendor status, or other benefit.Ā 

Ā What we don’t want to seeĀ 

Ā Please don’t use the contact methods outlined above for anything that isn’t product security related.Ā Ā  Communication that falls outside of scope will be deleted and will not receive a response.Ā  For non-product security related enquiries, please use the contact methods elsewhere on this website.Ā 

Modification or Termination of this Policy

Particle Measuring Systems may modify the terms of this policy or terminate the policy at any time

Activities Outside the Scope of this Policy

Particle Measuring Systems does not authorize, permit, or otherwise allow (expressly or implied) any person, including any individual, group of individuals, consortium, partnership, or any other business or legal entity, to engage in any security research or vulnerability or threat disclosure activity on or affecting Particle Measuring Systems products that is inconsistent with this policy or the law. If you engage in any activities that are inconsistent with this policy or other applicable law, you may be subject to criminal and/or civil liabilities.Ā 

Questions

Questions regarding this policy may be sent to the email addresses previously detailed. We also invite you to contact us with suggestions for improving this policy.Ā 

Ā 

Get the latest updates, insights, and resources straight to your inbox

Particle Measuring Systems logo
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

How can I help you today?