Vulnerability Disclosure Policy
XOS builds analytical X-ray instruments used in laboratory and process-control environments. We take the security of our products seriously and appreciate the work of security researchers, customers, and partners who report vulnerabilities to us in good faith.
Scope
This policy covers all XOS products containing software including but not limited to: R-Series and Petra benchtop analyzers, CCM and its XOS-operated cloud service, online process analyzers, and XOS software update packages. Reports concerning the xos.com web presence are accepted and forwarded to its operator.
How to Report
Send an email to productsecurity@xos.com that includes the following information:
- The product and software version affected. Product information can be found on the instrument label. Software version information is shown in the instrument UI (typically the Status screen).
- A description of the vulnerability
- Steps to reproduce or proof-of-concept.
- Any impact you assess.
Please do not include sensitive data in your report — no personal information, credentials, or customer data. To send sensitive technical material, encrypt it with our PGP key, also linked from our security.txt.
What We Commit To
We will acknowledge your report within 5 business days and follow up with our initial assessment within 10 business days. If the issue requires remediation, we will tell you when a fix is released, and credit you in the associated advisory unless you prefer to remain anonymous. We do not currently operate a paid bug bounty program.
Coordinated Disclosure
We ask that you give us 90 days from acknowledgment before public disclosure, and that you do not access, modify, or destroy data belonging to others, degrade a production instrument or the CCM cloud service, or use a vulnerability beyond the minimum needed to demonstrate it.
Out of Scope
While we encourage you to report any software or hardware vulnerability found in XOS products, the following items are out of scope for the coordinated disclosure timeline detailed on this page:
- Social engineering of XOS staff or customers
- Physical attacks on instruments
- Denial-of-service testing against the CCM cloud service
- Findings that require physical disassembly of an instrument to exploit
After a Fix
We publish security advisories describing fixed vulnerabilities, affected products and versions, severity, and the update that remediates them. Security updates for supported products are free of charge for the published support period of each product.
Terms
Information you submit under this policy is considered non-proprietary and non-confidential, and XOS may use it without restriction to understand, remediate, and publicly describe the issue. The response commitments above are good-faith targets, not a guarantee of a particular outcome. We may update this policy from time to time; the version published on this page is the current policy and applies to new reports.