Security

Responsible Disclosure

ELTON Cyber builds the platform medical device manufacturers use to find, verify, and disclose vulnerabilities. FDA expectations under section 524B include a coordinated vulnerability disclosure process, and we ask our customers to run one. So we run one too. This page explains how to report a security issue to us and what happens after you do.

Our commitment

We welcome good-faith security research on the systems we operate. If you find a vulnerability, we want to hear about it. We will work with you openly, fix what needs fixing, and credit your work if you want credit. Reports from researchers make our platform and our customers safer.

Scope

This policy covers eltoncyber.com and the ELTON platform, including the services we operate to support them. Systems run by third parties, such as hosting and analytics providers, are not covered here. Please report issues in those systems directly to the party that operates them.

How to report

Send your report through our contact page. Tell us the system or URL affected, the steps to reproduce the issue, and the impact you believe it has. Working proof helps us confirm the issue faster. Do not access, copy, or retain other people’s data; describing the path to it is enough.

What to expect

When you report a vulnerability to us:

  • We acknowledge your report within 2 business days.
  • We assess and reproduce the issue, then tell you what we found and how severe we judge it to be.
  • We agree on a coordinated disclosure timeline with you before anything is published. If remediation takes longer than planned, we keep you updated rather than going quiet.

Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue legal action against you or refer your activity to law enforcement, and if a third party raises a claim, we will state that your work was done under this policy. Good faith means you respect privacy, avoid destroying or altering data, avoid degrading our services, and give us a reasonable window to remediate before public disclosure.

Out of scope

The following are outside this policy and should not be tested:

  • Denial of service testing of any kind, including traffic floods and resource exhaustion.
  • Social engineering of ELTON employees, customers, or partners, including phishing.
  • Physical attacks against our offices, equipment, or people.
  • Findings from automated scanners with no demonstrated security impact.

Coordinated disclosure is the standard we hold medical device manufacturers to every day. Holding ourselves to it is the minimum.

Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Questions

Common questions about reporting a vulnerability to ELTON.

How do I report a security vulnerability to ELTON?

Send the report through the ELTON contact page. Tell us the system or URL affected, the steps to reproduce the issue, and the impact you believe it has. Working proof helps confirm it faster. Do not access, copy or retain other people's data while testing, because describing the path to it is enough.

How quickly does ELTON respond to a vulnerability report?

ELTON acknowledges a report within 2 business days. From there the team assesses and reproduces the issue, then tells you what was found and how severe it is judged to be. A coordinated disclosure timeline is agreed with you before anything is published, and if remediation runs long you get updates rather than silence.

Does ELTON offer safe harbor for security researchers?

Yes. Research that makes a good faith effort to follow the policy is considered authorized. ELTON will not pursue legal action or refer the activity to law enforcement, and if a third party raises a claim, ELTON will state the work was done under this policy. Good faith means respecting privacy, not altering or destroying data, and allowing a reasonable window to remediate.

What systems are in scope for ELTON's disclosure policy?

The policy covers eltoncyber.com and the ELTON platform, including the services ELTON operates to support them. Systems run by third parties, such as hosting and analytics providers, are not covered and should be reported to whoever operates them. ELTON asks its customers to run a disclosure process, so it runs one itself.

What testing is not allowed under the policy?

Four things are out of scope. Denial of service testing of any kind, including traffic floods and resource exhaustion. Social engineering of ELTON employees, customers or partners, including phishing. Physical attacks against offices, equipment or people. Findings from automated scanners with no demonstrated security impact.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON