Purpose
Oxford Cryosystems welcomes reports from customers, partners and security researchers who believe they have identified a vulnerability in our products, software or services. This policy explains what to report, how to share information safely, and how we aim to work with you while we investigate. It is intended to support coordinated disclosure so that potential issues can be assessed and addressed before technical details are made public.
What this policy covers
You can report a potential security vulnerability affecting an Oxford Cryosystems product or controller, software or firmware we supply, an associated communications interface or API, or a service we operate in connection with our products. This includes issues that may affect the confidentiality, integrity or availability of information, or the secure and reliable operation of a product.
If you are unsure whether an issue is within scope, please report it. Routine servicing, product faults and technical support questions should instead go through the Support Hub. We may direct reports concerning third-party products or services to the relevant provider.
How to report an issue
Use the security reporting form on the Product Security page. You may report an issue even if you do not have every detail requested by the form. Where possible, include:
- the affected product and its serial number, and relevant software or firmware version;
- a description of what you observed, when you discovered it and the potential impact;
- steps that may help us reproduce the issue; and
- relevant screenshots, logs or other evidence.
Indicate in the form if you believe the issue is currently being exploited. Please do not upload passwords, credentials, personal information, confidential experimental data or other sensitive material. Redact such information from evidence where possible. If we need it to investigate, we will discuss an appropriate way to share it.
Conducting Research Responsibly
Please act in good faith and comply with applicable law and the permissions you have to access or test a product or system. Keep testing proportionate to demonstrating the issue, and stop if your work risks disrupting equipment, services or customer operations.
In particular, please do not access, change, copy or disclose information that does not belong to you; conduct denial-of-service, phishing or social-engineering activity; or test equipment in a live production or safety-critical setting without explicit permission from its owner or operator. A public reporting channel does not itself authorise access to any system or third-party environment.
If you identify a vulnerability, please give us a reasonable opportunity to investigate and address it before publishing technical details. We welcome a conversation about the timing and content of any disclosure, taking account of the risk to affected users.
How we handle reports
We will review reports we receive, assess whether an issue can be reproduced, and consider its potential impact and the products affected. We may ask for further information. Where appropriate, we will work on a correction or mitigation and provide relevant guidance to affected customers.
Some reports may be duplicates, may concern an issue we cannot reproduce, or may fall outside this policy. We will explain our assessment where practicable and where we have a way to contact you. Investigation and resolution times vary with the complexity of the issue and the testing required. We may publish an advisory or other notice when that is an appropriate way to inform affected users.
Handling your information
We will use information submitted through the reporting form to assess and respond to the report, and may share it with people who need it for investigation, remediation or applicable legal obligations. Please see our Privacy Policy for information about our handling of personal data.
Do not publish another person’s confidential information or personal data in connection with a report. If you wish to be credited in a public notice, tell us; any acknowledgement will be discussed with you before publication.