Reporting a Security Vulnerability
Effective date: September 11, 2026
If you believe you have found a security vulnerability in an Alicat product, we want to hear from you. This page explains how to tell us, what we will do, and how we will let you know about fixes.
It applies whether you are an Alicat customer who has noticed something on your own network, a security researcher, or a partner or distributor. Contacting us about a vulnerability does not in itself affect your warranty or support entitlement.
This page is for security vulnerabilities. For general product support, please use [email protected].
How to report
Email [email protected]. The mailbox is read by Alicat staff, not by an automated system.
If you would rather not use email, you can write to us at the address below or call +1 520-290-6060 and ask for the product security team.
Alicat Scientific, Inc.
7641 N. Business Park Drive
Tucson, Arizona 85743, United States
Please include, as far as you are able:
- The product, model, and software or firmware version affected.
- What you observed, and what you think an attacker could do with it.
- How to reproduce it, including any configuration, network setup, or test code.
- Whether you believe the vulnerability is already being exploited. If you do, say so at the top of your report. We have legal obligations that start the moment we learn this, so it changes how quickly we act.
- How you would like to be credited, if at all.
Reports in English are preferred. You do not need a fix, a working exploit, or a CVE to report; a clear description of what you saw is enough.
Please do not include process data, customer data, or personal data beyond what is needed to show the problem.
What we will do
- Acknowledge your report within 3 business days. If you do not hear from us in that time, please resend. Do not assume the report was received and ignored.
- Give you an initial assessment within 10 business days: whether we have reproduced the issue and what we intend to do. If reproducing it needs hardware we have to set up, we will tell you and give you a date.
- Keep you updated at least every 30 days while we work on a fix.
- Tell you when a fix ships, and which version carries it.
- With your agreement, credit you in the security advisory using the name you choose. We will not name you without your agreement.
These are the timescales we work to. They depend on the detail in your report and, for hardware issues, on the availability of test equipment. They are targets, not guarantees, and they do not form part of any contract.
We do not pay for vulnerability reports.
How we notify customers
When a fix or mitigation is available, we publish a security advisory at alicat.com/security-advisories. Each advisory identifies the affected products and versions, the nature and severity of the issue, and the fixed version or the mitigation to apply.
If we learn that a vulnerability in an Alicat product is being actively exploited, or of a security incident affecting the security of an Alicat product, we will notify affected users of the issue and of any mitigation or corrective measures available, using the contact details we hold for them, and publish an advisory. We also notify our distributors so they can pass advisories to their customers.
To receive advisories directly, subscribe at alicat.com/newsletter-sign-up. Subscribing is the most reliable way to hear from us, particularly if you bought your equipment through a distributor.
We may hold an advisory briefly where publishing it before customers have had a chance to update would put them at more risk than the delay does. We will not use this to avoid disclosure.
Coordinated disclosure
We ask anyone who reports a vulnerability to give us 90 days from the date we acknowledge it before disclosing it publicly, so that customers have a fix available before the details are known.
If a fix will take longer than 90 days, we will explain why and propose a revised date. Some of our products are instruments installed in customer facilities, and updating them can require a scheduled maintenance window rather than an automatic download. We would rather explain a delay than ask you to wait indefinitely without reason.
If you believe the vulnerability is being actively exploited, or that users are at immediate risk, tell us and we will treat the timeline as negotiable. We will not ask you to delay disclosure indefinitely, and we will not use this request to avoid fixing a problem.
Third-party components
Alicat products include third-party and open-source software. If a vulnerability originates in one of those components, we will assess the impact on our products, coordinate with the component’s maintainers where appropriate, and fix the issue in our products. If you have found a problem in a third-party component and are not sure whether it affects an Alicat product, report it and we will check.
Testing Alicat products
Alicat instruments and gas mixers are installed in laboratories and industrial processes, sometimes connected to live gas supplies. Never test a device that is in service. Interfering with an instrument in service can create a safety hazard, not just a security one.
If you want to test an Alicat product for vulnerabilities:
- Only test equipment and software you own, or that you have the owner’s written permission to test. This page does not give you permission to test a customer’s installed equipment.
- Do not access, change, or take data that is not yours.
- Stop once you have confirmed the vulnerability. Do not use it further, and do not disrupt or damage any system in service.
If you report a vulnerability in good faith and follow this page, Alicat Scientific, Inc. will not bring legal action against you in connection with that research.
This assurance is given by Alicat Scientific, Inc. and covers its own rights only. It does not protect you from action by anyone else, including our customers, distributors, or the owners of equipment you test. It does not apply where we reasonably conclude that you have not acted in good faith or have not followed this page, and in that case Alicat reserves all of its rights. Nothing here prevents Alicat from meeting a legal obligation, a court order, or a lawful request from an authority. Alicat may change or withdraw this statement; the version in effect when you carry out the research applies to it.
If you are unsure whether what you plan to do is covered, ask us first at [email protected].
Scope
In scope: FlowVision 2, MXM Software, Calibrate, Alicat Bootloader, Alicat Connect, the MXM gas mixer, Alicat instrument firmware, and the software download and update services Alicat operates.
If you run a vulnerability scanner on your own network and it flags an Alicat product, send us the output. Many scanner findings on embedded devices are false positives, and we would rather check than have you guess. A scanner report on its own is not a confirmed vulnerability, so we may close it once we have checked.
Not covered by this process:
- Alicat’s corporate IT systems, website, and email. Reports about these are welcome at the same address but are handled separately.
- Third-party services Alicat does not operate.
- Denial-of-service, load, or resource-exhaustion testing against any system in service, and social engineering or physical attacks against Alicat staff or facilities. These are not accepted as research methods.
- Products that have passed their security support end date. See Security support periods below.
If you are not sure whether something is in scope, report it and ask.
Security support periods
Every Alicat product has a security support period: the time during which we handle vulnerabilities and provide security updates for it. It is counted from the date your unit shipped, not from when the product was launched, so two units of the same model bought years apart have different end dates.
Every Alicat product listed under Scope is supported for at least 5 years. For instruments and the MXM gas mixer, that runs from the date your unit shipped. For our software applications, it runs from the release date of the version you install.
The end date for your unit, given as a month and year, is shown on your order acknowledgement and delivery paperwork, and in the documentation supplied with the product. These durations apply to units shipped and software released from December 11, 2026.
Five years is the minimum we commit to. We often continue to issue security updates beyond it, and we may extend a published support period at any time. We will not shorten one that has already been published.
What security support covers. During the support period we handle reported vulnerabilities, issue security updates, and publish advisories. Security fixes are delivered in the current release of the software or firmware, so applying a fix may require updating to a current version.
What it does not cover. Security support is separate from calibration, repair, spare parts, and technical support, which continue under your normal service and warranty terms and are not affected by this page. It does not mean new features.
Availability of updates. Once we publish a security update we keep it available for download for at least ten years after the product was placed on the market, or for the rest of the support period, whichever is longer.
When the period ends. We will still accept and assess reports about the product, and we may publish an advisory describing the issue and any mitigation, but we may not issue a fix. Where the product can display it, we show a notice once support has ended.
If you are not sure of the support end date for equipment you already own, contact [email protected] with the serial number and we will tell you.
Legal notices
Status of this page. This page describes how Alicat handles vulnerability reports. It is a statement of our practices, not an offer, and it does not form a contract or create rights for anyone else. It is not a warranty and does not change the terms of sale, license agreements, or warranties that apply to Alicat products.
Your report. By sending us a report you confirm that you are entitled to share the information and any material in it, and you give Alicat a non-exclusive, worldwide, royalty-free, perpetual license to use, copy, and adapt the report and anything sent with it in order to investigate and fix the issue and to prepare and publish advisories.
Confidentiality. We handle reports carefully and will not publish your identity without your agreement. Reports are not confidential to Alicat unless we agree otherwise in writing, and sending one does not create any confidentiality, employment, agency, or partnership relationship. We may share a report, including its technical detail, with the maintainers of affected third-party components and with regulators, national cybersecurity authorities, and other bodies where the law requires or allows it.
No obligation. We are not obliged to act on any particular report, to fix an issue in a particular way, or to fix it at all. We do not pay for reports, and we take on no obligation to you by receiving one.
Export control and sanctions. Alicat products, software, security updates, and technical information are subject to United States export control and sanctions laws. We may decline to correspond with, or to supply updates or technical information to, any person or destination where doing so would breach those laws.
EU Cyber Resilience Act. Alicat Scientific, Inc. is a manufacturer of products with digital elements for the purposes of Regulation (EU) 2024/2847 (the Cyber Resilience Act) and reports actively exploited vulnerabilities and severe incidents to the EU single reporting platform where that regulation requires.
Personal data. Personal data you provide when reporting is used to communicate with you about the report, to credit you if you have agreed, and to meet our legal obligations. Alicat is based in the United States, so your data is processed there, and it may be shared with authorities as described above. See Privacy Policy.
Changes. We may update this page. The version in effect when you report applies to your report.
Version 1.6, published September 11, 2026
Alicat global offices
- US office and service center: +1 888-290-6060
- Email: [email protected]
- Website: alicat.com
- Address:
7641 N. Business Park Drive
Tucson, AZ 85743 USA
- China office and service center: +86 21-6151-9020
- Office email: [email protected]
- Service center email: [email protected]
- Website: alicat.com.cn
- Address:
3rd Floor, Building 18
FAMILY Science and Technology Innovation Park
No. 155 Yuanke Road
Minhang District
Shanghai, PRC 201109
- Europe office and service center: +31 262-031-651
- Email: [email protected]
- Website: alicat.com
- Address:
Geograaf 24
6921 EW
Duiven, The Netherlands
- Thane office and service center: +91 22460-81434
- Surat office and service center: +91 79902-58717
- Email Inquiries: [email protected]
- Website: alicat.com
- Address:
Alicat Scientific India Pvt. Ltd.
101, Hamilton A Bldg,
Near Hiranandani Hospital, Hiranandani Estate, Patli Pada, Ghodbunder Road,
Thane West-400607
Maharashtra, India
GST No.: 27AAWCA5866D1Z6
Surat Service Center
322-323 Laxmi Enclave 2, Laxmi Circle,
opposite Gajera School, Rajanand Society, Ram Nagar Society,
Katargam, Surat – 395004
Gujarat, India