Security
Report a security vulnerability
Our coordinated vulnerability disclosure policy for ProcessView+ and related products.
How to report
Email support@chamberdatahub.com with "Security" in the subject line. A person reads it.
You do not need to be a customer to report a vulnerability, and we will not ask you to sign an NDA. Both are common barriers, and both stop reports reaching the people who can fix things.
Please never test against equipment in service
These products control heating and cooling equipment that can reach hazardous temperatures, and which may be running experiments, sterilization cycles, or heat-treat processes worth a great deal to someone.
ProcessView+ includes a Simulation Mode with a built-in virtual controller. It runs the full product, including the electronic signature workflow, with no hardware attached. Please use it. It is in the shipping build, so you do not need anything from us to start. If you need something Simulation Mode cannot provide, contact us and we will discuss a test arrangement.
What to include
- The product and version. Help → About shows both, including the build identifier — please quote it exactly.
- What the vulnerability is, and what an attacker could do with it.
- How to reproduce it, in enough detail that we can see it ourselves.
- The environment: Windows version, controller types, network layout, and which optional features were enabled (MQTT, external database, file transfer, Part 11 mode).
- Your own assessment of the impact.
- How you wish to be credited, or that you would rather not be.
- Any disclosure deadline you intend to apply, so we can tell you early if we cannot meet it.
What happens after you report
Response targets are being set and are not yet published. Rather than publish a number we have not committed to, this table is marked as pending. In the meantime, reports are read and answered by a person — send yours and you will hear back.
Response stages
| Acknowledge | We confirm we have your report and that a person has read it. TODO — timeline to be set |
| Triage | We reproduce the issue, establish which products and versions are affected, and assess severity. TODO — timeline to be set |
| Keep you informed | While we are working on it, we tell you where it stands — including when the answer is that it is still in progress. TODO — timeline to be set |
| Remediate | We ship a fix, or tell you what we are doing instead and why. TODO — timeline to be set |
| Disclose | We publish an advisory, credit you as you have asked to be credited, and notify registered security contacts and distributors. TODO — timeline to be set |
Safe harbor for good-faith research
If you research and report in good faith under this policy, we will not take legal action against you. If a third party brings action against you for research conducted under this policy, we will make it known that your activity was authorized.
That protection depends on you:
- Avoiding privacy violations and destruction of data.
- Testing only systems you own or have permission to test — see the note above about equipment in service.
- Not retaining anyone else's data. If you encounter it, stop and tell us.
- Not using social engineering, phishing, or denial of service.
- Reporting promptly once you have found something.
- Not conditioning disclosure on payment. We do not operate a bug bounty, and a report that arrives with a price attached is not a report.
Scope
In scope:
- ProcessView+
- ProcessView HV
- The Remote PC MQTT Client
- The Server Software
- chamberdatahub.com and downloads.chamberdatahub.com
Out of scope, and why — because "out of scope" without a reason reads as evasion:
- Watlow and Future Design controllers. We do not manufacture them. If you have found something in a controller itself, tell us anyway and we will help you find the right contact.
- The Modbus protocol’s lack of authentication or encryption. This is a property of the protocol the controllers speak, not a defect in our software. No software product can fix it. Network segmentation is the control.
- Customer deployments and configurations. How a particular site has installed, networked, or configured the software belongs to that site. If you believe our defaults or our guidance lead people into a bad configuration, that is in scope — tell us.
- Third-party services we use but do not control. Report those to the service concerned. We will help if you are not sure who that is.
- Findings that require physical access to an already-compromised machine. If an attacker already has administrative control of the PC, they have the data by definition.
- Automated scanner output with no demonstrated impact. We read every report, but a scanner banner alone does not tell us whether anything is actually wrong.
Where advisories are published
Advisories are published at chamberdatahub.com/security/advisories. None have been issued to date, and that page says so.
Register a security contact
If you run ProcessView+ in a regulated or production environment, please give us a named person or a monitored role address to notify when an advisory affects you. Without one we have no reliable way to reach you during an incident — and a purchase record is not a security contact, because the person who bought the software is often not the person who needs to know.
Email support@chamberdatahub.com with your company, the products and versions you run, and the address to use.