Product Security
We build the BioCharger to be secure, and we keep it secure for as long as we support it. This page tells you how to report a security problem to us, what we will do about it, and how long you can expect to receive security updates.
Report a security issue
If you believe you have found a security vulnerability in the BioCharger or in our online services, please submit a report using the form below.
You do not need an account, and you do not need to give us your name or any personal details to make a report.
Please include, as much detail you can with regards to the following:
- What you found, and what an attacker could do with it
- The steps to reproduce what you found
- Anything that helps us confirm it — a log excerpt, a screenshot, a short video
Please do not include personal data belonging to other people, and please do not access, modify, or delete data that is not your own.
What happens after you report
| When | What we do |
|---|---|
| Within 3 business days | We acknowledge your report and give you a reference number |
| Within 10 business days | We tell you whether we have confirmed the issue and what we intend to do |
| At least every 30 days | We send you a status update, until the issue is resolved or we tell you we are closing it |
If we decide the issue is not a vulnerability, we will tell you why rather than simply closing the report.
Working with us
We welcome reports from security researchers and we will not pursue legal action against you for good-faith research, provided you:
- Only test devices and accounts that belong to you
- Do not access, change, or delete data belonging to anyone else
- Do not degrade or disrupt our services or other people's devices
- Give us a reasonable opportunity to fix the issue before you discuss it publicly
- Do not use the issue for anything beyond demonstrating that it exists
We do not currently operate a paid bug bounty.
What is in scope
In scope
- BioCharger device firmware
- Client Cloud Portal (mycloud.biochargerng.com): The primary user management platform for account administration, client profiles, and recipe library synchronization.
- Public Web & E-Commerce Properties (biocharger.com): Including our corporate website, public resources, and online parts store (biocharger.com/product-category/parts)
- Support & Compliance Portal (support@biocharger.com): Our configuration, form workflows, and custom portal content. (Note: Vulnerabilities in the core HubSpot platform itself should be reported directly to HubSpot.)
Out of scope
- Social engineering of ABT staff, customers, or suppliers
- Physical attacks on ABT premises
- Denial-of-service testing against our services
- Reports generated solely by an automated scanner, with no demonstrated impact
- Vulnerabilities in third-party services or platforms we do not directly operate (e.g., core infrastructure issues in AWS or HubSpot itself).
Security Inquiries
To submit a security-related inquiry, report a vulnerability, or contact our compliance team, please use the form below:
Who we are
Advanced Biotechnologies, LLC.860 Route 134, Suite 3
S. Dennis, MA 02660