Security & Vulnerability Disclosure
Intelligent Bio Solutions Inc. is committed to the security and integrity of our reader devices. We work continuously to test, monitor, and strengthen the security of our hardware and software, and we value the contributions of independent researchers, customers, and partners who help us identify potential weaknesses before they can be exploited.
This page explains how to report a suspected security vulnerability affecting our reader, what to expect after you submit a report, and how we handle disclosure.
Scope
This disclosure process covers security vulnerabilities related to the Intelligent Fingerprinting Drug Screening Reader, including its firmware, software, and any connection used to operate it.
Reports about our corporate website, general IT infrastructure, or matters unrelated to the reader should be directed to our general contact channels rather than submitted here.
How to Report a Vulnerability
If you believe you have identified a security vulnerability affecting the reader, please use one of the two methods below to notify us. Submitting via the form is the fastest way to get your report to the right team; however, you may also email us directly.
Option 1
Submit the Form
To help us evaluate and act on your report quickly, please complete the form, providing as much additional information needed for us to properly assess the potential vulnerability.
Option 2
Email Us
Send your report, including the information below, to security@ibs.inc.
- Your name and contact information, including email, phone number, and organization.
- Reader model and software version.
- A clear description of the vulnerability and its potential impact, including when, where and how it was discovered.
- Step-by-step instructions to reproduce the issue.
- Any supporting evidence: screenshots, logs etc.
- Whether the vulnerability has been shared with, or disclosed to, any other party.
What Happens After You Report
Once we receive your report, our security team will:
- Acknowledge receipt of your report within 48 hours.
- Investigate the reported vulnerability within five (5) business days, assessing its severity and potential impact.
- Provide remediations, patches, and updates via the appropriate channels, including email notifications, our company website, and direct contact where applicable.