Product Security & Coordinated Vulnerability Disclosure (CVD) Process

Protecting Our Customers Through Product Security

At X-Rite Pantone, protecting our customers, products, and data is a priority. We are committed to building and maintaining secure products and services that help our customers operate with confidence.

Our global Product Security Team continuously evaluates potential security risks, reviews reported vulnerabilities, and works with internal experts to address validated issues. As part of this commitment, we maintain a Coordinated Vulnerability Disclosure (CVD) process that enables customers and security researchers to responsibly report potential security concerns.

Through open collaboration and responsible disclosure, we can continually improve the security and resilience of our products and services.

Reporting a Security Concern

If you believe you have identified a potential cybersecurity vulnerability in an X-Rite Pantone product or service, we encourage you to report it to our Product Security Team for review.

This process applies specifically to the reporting of potential cybersecurity vulnerabilities in X-Rite Pantone products and services.

For customer support requests, technical documentation, regulatory inquiries, or other product assistance, please contact X-Rite Pantone Support.

How to Report a Potential Vulnerability

Potential security vulnerabilities or privacy issues related to an X-Rite Pantone product should be reported to: XRPProductSecurity@xrite.com.

To help our team investigate reported concerns efficiently, please include the following information whenever possible:

For your protection, please do not include sensitive information such as personal identifiable information (PII), usernames, passwords, customer data, or sample information in any submission.

What Happens After You Submit a Report

Our Product Security Team reviews each submission and works with the appropriate specialists to evaluate and validate reported findings.

Upon receiving a vulnerability report, X-Rite Pantone will:

We appreciate the efforts of customers and security researchers who help us identify and responsibly disclose potential vulnerabilities.

Responsible Security Research Guidelines

To help ensure safe and responsible security research, please review the following guidelines.

When conducting security testing, please avoid activities that could cause harm to customers, products, systems, or data. Vulnerability testing may negatively impact product performance or operation. For that reason, testing should not be performed on actively deployed production systems. Products that have undergone security testing should not subsequently be used in a production environment.

If you have questions about appropriate testing activities, please contact an X-Rite Pantone representative before proceeding.

Additional Information

X-Rite Pantone reserves the right to modify its Coordinated Vulnerability Disclosure process at any time and may make exceptions on a case-by-case basis. While no specific level of response can be guaranteed, verified vulnerabilities may be acknowledged with attribution to the reporting researcher upon request.

Important: Do not include sensitive information, including PII, usernames, passwords, or customer data, in any materials submitted to X-Rite Pantone. All testing activities must comply with applicable laws and regulations.

By contacting X-Rite Pantone, you agree that information submitted will be governed by X-Rite Pantone's Privacy Policy and Online Terms of Use. Information submitted through this process will be considered non-proprietary and non-confidential and may be used by X-Rite without restriction.



Need a Quote? Contact Sales(888) 800-9580

Technical Questions? Contact Support(888) 826-3042