Sea-Bird takes the security of our products seriously and appreciate the work of security researchers, customers, and partners who report vulnerabilities to us in good faith.
Scope
This policy covers all Sea-Bird products containing software including but not limited to: CTD Systems, Fluorometers, Radiometers, and all active supporting software packages.
How to Report
Send an email to productsecurity@seabird.com that includes the following information:
- The product and software version affected.
- A description of the vulnerability.
- Steps to reproduce or proof-of-concept.
- Any impact you assess.
- Social engineering of Sea-Bird staff or customers
- Physical attacks on instruments
- Denial-of-service testing against Sea-Bird cloud services
- Findings that require physical disassembly of an instrument to exploit
Please do not include sensitive data in your report, such as personal information, credentials, or customer data. To send sensitive technical material, encrypt it with our PGP key, also linked from our security.txt.
What We Commit To
We will acknowledge your report within 5 business days and follow up with our initial assessment within 10 business days. If the issue requires remediation, we will tell you when a fix is released. We do not currently operate a paid bug bounty program.
Coordinated Disclosure
We ask that you give us 90 days from acknowledgment before public disclosure, and that you do not access, modify, or destroy data belonging to others, degrade a production instrument, or use a vulnerability beyond the minimum needed to demonstrate it.
Out of Scope
While we encourage you to report any software or hardware vulnerability found in Sea-Bird products, the following items are out of scope for the coordinated disclosure timeline detailed on this page:
Terms
Information you submit under this policy is considered non-proprietary and non-confidential, and Sea-Bird may use it without restriction to understand, remediate, and publicly describe the issue. The response commitments above are good-faith targets, not a guarantee of a particular outcome. We may update this policy from time to time; the version published on this page is the current policy and applies to new reports.