Security

Responsible Disclosure

ELTON Cyber builds the platform medical device manufacturers use to find, verify, and disclose vulnerabilities. FDA expectations under section 524B include a coordinated vulnerability disclosure process, and we ask our customers to run one. So we run one too. This page explains how to report a security issue to us and what happens after you do.

Our commitment

We welcome good-faith security research on the systems we operate. If you find a vulnerability, we want to hear about it. We will work with you openly, fix what needs fixing, and credit your work if you want credit. Reports from researchers make our platform and our customers safer.

Scope

This policy covers eltoncyber.com and the ELTON platform, including the services we operate to support them. Systems run by third parties, such as hosting and analytics providers, are not covered here. Please report issues in those systems directly to the party that operates them.

How to report

Send your report through our contact page. Tell us the system or URL affected, the steps to reproduce the issue, and the impact you believe it has. Working proof helps us confirm the issue faster. Do not access, copy, or retain other people’s data; describing the path to it is enough.

What to expect

When you report a vulnerability to us:

  • We acknowledge your report within 2 business days.
  • We assess and reproduce the issue, then tell you what we found and how severe we judge it to be.
  • We agree on a coordinated disclosure timeline with you before anything is published. If remediation takes longer than planned, we keep you updated rather than going quiet.

Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue legal action against you or refer your activity to law enforcement, and if a third party raises a claim, we will state that your work was done under this policy. Good faith means you respect privacy, avoid destroying or altering data, avoid degrading our services, and give us a reasonable window to remediate before public disclosure.

Out of scope

The following are outside this policy and should not be tested:

  • Denial of service testing of any kind, including traffic floods and resource exhaustion.
  • Social engineering of ELTON employees, customers, or partners, including phishing.
  • Physical attacks against our offices, equipment, or people.
  • Findings from automated scanners with no demonstrated security impact.

Coordinated disclosure is the standard we hold medical device manufacturers to every day. Holding ourselves to it is the minimum.

Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo