ELTON Cyber builds the platform medical device manufacturers use to find, verify, and disclose vulnerabilities. FDA expectations under section 524B include a coordinated vulnerability disclosure process, and we ask our customers to run one. So we run one too. This page explains how to report a security issue to us and what happens after you do.
We welcome good-faith security research on the systems we operate. If you find a vulnerability, we want to hear about it. We will work with you openly, fix what needs fixing, and credit your work if you want credit. Reports from researchers make our platform and our customers safer.
This policy covers eltoncyber.com and the ELTON platform, including the services we operate to support them. Systems run by third parties, such as hosting and analytics providers, are not covered here. Please report issues in those systems directly to the party that operates them.
Send your report through our contact page. Tell us the system or URL affected, the steps to reproduce the issue, and the impact you believe it has. Working proof helps us confirm the issue faster. Do not access, copy, or retain other people’s data; describing the path to it is enough.
When you report a vulnerability to us:
If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue legal action against you or refer your activity to law enforcement, and if a third party raises a claim, we will state that your work was done under this policy. Good faith means you respect privacy, avoid destroying or altering data, avoid degrading our services, and give us a reasonable window to remediate before public disclosure.
The following are outside this policy and should not be tested:
Coordinated disclosure is the standard we hold medical device manufacturers to every day. Holding ourselves to it is the minimum.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.
Send the report through the ELTON contact page. Tell us the system or URL affected, the steps to reproduce the issue, and the impact you believe it has. Working proof helps confirm it faster. Do not access, copy or retain other people's data while testing, because describing the path to it is enough.
ELTON acknowledges a report within 2 business days. From there the team assesses and reproduces the issue, then tells you what was found and how severe it is judged to be. A coordinated disclosure timeline is agreed with you before anything is published, and if remediation runs long you get updates rather than silence.
Yes. Research that makes a good faith effort to follow the policy is considered authorized. ELTON will not pursue legal action or refer the activity to law enforcement, and if a third party raises a claim, ELTON will state the work was done under this policy. Good faith means respecting privacy, not altering or destroying data, and allowing a reasonable window to remediate.
The policy covers eltoncyber.com and the ELTON platform, including the services ELTON operates to support them. Systems run by third parties, such as hosting and analytics providers, are not covered and should be reported to whoever operates them. ELTON asks its customers to run a disclosure process, so it runs one itself.
Four things are out of scope. Denial of service testing of any kind, including traffic floods and resource exhaustion. Social engineering of ELTON employees, customers or partners, including phishing. Physical attacks against offices, equipment or people. Findings from automated scanners with no demonstrated security impact.