Product security
IPRATECH designs and supports CytoSys bioprocess controllers (CytoSys IOFlexMulti and its applications). We take the security of our products seriously and comply with the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
Report a vulnerability If you believe you have found a security vulnerability in one of our products, please tell us:
- e-mail security@ipragroup.com, or
- our Helpdesk at https://helpdesk.ipragroup.com/, category "Security / Vulnerability".
Please include the product and its versions (HMI, supervisor and firmware versions are shown in Settings → About), a description, the steps to reproduce, and the impact you expect. We acknowledge every report within 72 hours. Read our Coordinated Vulnerability Disclosure Policy.
Security advisories Fixed vulnerabilities are published on our security advisories page. Customers under support are also notified through the Helpdesk.
Support period Support period: 10 years from the placing on the market of the product. During this period we provide security updates free of charge, as signed update packages that can be applied offline from the controller's interface. The support period has been determined based on the expected operational lifetime of the controller, reasonable customer expectations, the intended laboratory use of the product, the expected lifetime of its hardware components, the availability of the software operating environment and the support periods of third-party components. Warranty: 1 year.
Coordinated Vulnerability Disclosure Policy IPRATECH — products with digital elements (EU Cyber Resilience Act, Regulation (EU) 2024/2847, Article 13(2) and Annex I Part II). Follows ISO/IEC 29147 and ISO/IEC 30111. Version 1.0 — October 2026.
1. Our commitment IPRATECH welcomes reports of vulnerabilities in its products (CytoSys IOFlexMulti and its applications: bioprocess controllers with a web interface, Modbus supervisor and board firmware) and handles them in a coordinated way, in the interest of our users.
2. Scope In scope: product versions within their support period — interface, supervisor, board firmware, system services, operating system and components delivered with the controller, and the update chain (signed update packages). Out of scope: installations modified by third parties outside IPRATECH procedures; components not supplied by IPRATECH (site network, client workstations); denial-of-service testing or any action against equipment in production (running process); social engineering of our staff or customers.
3. How to report E-mail security@ipragroup.com or use the Helpdesk at https://helpdesk.ipragroup.com/ (category "Security / Vulnerability"). Please provide the product and versions, a description, steps to reproduce, the expected impact and your contact details.
4. What you can expect from us
| Step | Target |
|---|---|
| Acknowledgement of your report | within 72 hours |
| Initial assessment and severity rating | within 10 working days |
| Fix for a critical vulnerability (CVSS ≥ 9.0, actively exploited, or unauthenticated remote access) | within 14 days |
| Fix for a high-severity vulnerability (CVSS 7.0–8.9) | within 30 days |
| Fix for other vulnerabilities | next release |
| Status updates to the reporter | until resolution |
| Coordinated disclosure (security advisory) | when the fix is released, at a date agreed with the reporter |
Security fixes are provided free of charge as signed update packages, separately from functional changes where possible.
5. Safe harbour We will not take legal action against researchers who act in good faith, stay within the scope above, do not harm the availability or the confidentiality of other people's data, and follow coordinated disclosure.
6. Credit With your consent, we credit you in the security advisory. You may remain anonymous.
7. Disclosure and regulatory reporting We publish a security advisory when the fix is released. Actively exploited vulnerabilities and severe incidents are also reported to the authorities through the ENISA Single Reporting Platform, as required by Article 14 of the Cyber Resilience Act.
Security advisories
| ID | Published | Title | Severity | Affected / fixed versions |
|---|---|---|---|---|
| — | — | No advisory published yet. | — | — |