Your cart is empty.
Tecan uses cookies to improve our website. By continuing to browse our website, you accept our cookie policy.
At Tecan, we are committed to protecting the security, privacy, and integrity of our products, services, and digital platforms. We recognize the important role that security researchers and the broader security community play in helping identify potential vulnerabilities.
If you believe you have discovered a security vulnerability related to a Tecan product, service, website, or application, we encourage you to report it to us responsibly so that we can investigate and address the issue.
Tecan operates a Coordinated Vulnerability Disclosure (CVD) process for handling reported vulnerabilities. We ask that reporters share details with us confidentially and refrain from public disclosure until we have had a reasonable opportunity to investigate and address the issue, or until we have mutually agreed on a disclosure timeline with the reporter.
This approach is consistent with recognized industry standards for vulnerability disclosure and handling, including ISO/IEC 29147 and ISO/IEC 30111, and supports Tecan's compliance with applicable cybersecurity and product regulatory requirements, including, where applicable, the EU Cyber Resilience Act.
Please provide as much information as possible, including:
When a vulnerability report is submitted in good faith, Tecan will:
For purposes of this process, good-faith reporting means security research conducted solely to identify and report a potential vulnerability, while avoiding harm to Tecan, its customers, users, employees, business partners, products, systems, services, and data.
We appreciate the efforts of the security research community and thank individuals who help us improve the security of our solutions through responsible disclosure.
Confidentiality: Tecan will handle vulnerability reports with appropriate confidentiality. Information may, however, be shared where reasonably necessary to investigate, assess, remediate, or disclose the vulnerability, comply with applicable law or regulatory requirements, or protect Tecan, its customers, users, and other affected parties.
Use of submitted materials: By submitting a report, you confirm that you are entitled to provide the submitted information and materials and permit Tecan to use, reproduce, analyze, and share them as reasonably necessary to investigate, assess, remediate, and communicate about the reported vulnerability.
No compensation: Tecan does not operate a bug bounty program. Unless expressly agreed otherwise in writing, Tecan does not offer financial compensation or other rewards for vulnerability reports submitted through this process.
If you believe you have discovered a security vulnerability related to a Tecan product, service, website,
or application, please contact us.
Our security team will review the information and contact you if additional details are required.
This communication channel is monitored Monday throught Friday from 8:00 to 1700 CET.
The Tecan "security.txt" file can be found here.