Home / Product Security
Product
Security
Quantifi Photonics is committed to delivering secure, reliable products that help customers operate with confidence. Security is embedded throughout our product lifecycle, from secure design and development to continuous vulnerability assessment and mitigation. Guided by industry-recognized frameworks and rigorous governance, our Product Security Program helps safeguard data, protect critical operations, and address emerging cybersecurity risks. By integrating security, privacy, and responsible technology practices into everything we build, we support the trust our customers place in Quantifi Photonics every day.
Coordinated vulnerability disclosure
Report a security vulnerability
Quantifi Photonics instruments sit on the production lines and test benches of the world’s leading photonics manufacturers, universities and research organisations. If you have found a security vulnerability in one of our instruments, or in the drivers and software we publish, we want to hear from you. This page explains what to report, how to report it, and what happens next.
Secure intake form. No account required.
How to report
Our secure online intake form, the single channel for vulnerability reports.
Acknowledgement
Automated confirmation with a Tracking ID immediately on submission.
Who handles it
A named contact from the Quantifi Photonics product security team.
Cost to you
Reporting is free. We do not operate a paid bug bounty programme.
What you can expect
Our commitment to you
Quantifi Photonics is a Teradyne company. Vulnerability reports are handled by the Teradyne Product Security Incident Response Team (PSIRT) together with the Quantifi Photonics engineering organisation, under a single Coordinated Vulnerability Disclosure (CVD) process. When you report a vulnerability to us in good faith, we commit to the following.
We will respond
Every report receives an automated acknowledgement with a Tracking ID. A member of our product security team then reviews it and follows up with you directly.
We will keep you informed
Once we have assessed your report, we will tell you whether we have reproduced the issue, how we have rated it, and what we intend to do about it.
We will not pursue you
If you follow the rules of engagement below, we will treat your research as authorised and will not initiate legal action or a law enforcement referral against you. See safe harbour.
We will credit you
Where you would like it, and where a public advisory is issued, we are glad to credit you by name or handle. You may also ask to remain anonymous.
Scope
What is in scope
Security vulnerabilities in Quantifi Photonics test instruments and the software that runs on and alongside them. Examples include:
- Instrument platforms: PXI and PXIe modules, and MATRIQ and EPIQ instruments.
- Opto-electrical and transceiver test instruments: coherent optical communications instruments, digital sampling oscilloscopes, optical to electrical converters, and passive component integration modules.
- Optical bench instruments: laser sources and amplifiers including swept and broadband sources, optical spectrum analyzers, variable optical attenuators, optical switches, optical power meters, polarization conditioners, and Doppler Series instruments for photonic Doppler velocimetry.
- Drivers, software and APIs: instrument drivers, control and measurement applications, calibration software, SCPI command sets, and the Python, LabVIEW and MATLAB bindings and automation libraries we publish.
- System controllers and instrument firmware: the host PC or chassis controller and the operating system image as we ship and configure it, module and instrument firmware, FPGA images and bootloaders, onboard services, and debug or service interfaces.
- Remote control and integration interfaces: SCPI, VISA and other instrument control protocols, network services, remote access features, and the interfaces used to integrate an instrument into a production line, test cell, prober or handler.
- Quantifi Photonics operated internet facing services: our websites, customer and support portals, and the drivers, software and manuals download infrastructure.
- Update and supply chain integrity: software and firmware update mechanisms, signing and verification, licensing enforcement, and any way to get unauthorised code onto an instrument.
These are examples, not a complete list. Our portfolio changes over time, so if your finding affects a Quantifi Photonics product that is not named here, please submit it anyway and name the product in the form. We will route it to the right team.
Scope
What is out of scope
The following are generally not accepted. We may still review a report in this list if you can demonstrate concrete security impact, so if you are in doubt, submit it and tell us why it matters.
- Raw output from an automated scanner with no demonstrated exploitability or impact.
- Missing HTTP security headers, cookie flags, TLS configuration preferences, or SPF, DKIM and DMARC findings with no demonstrated impact.
- Behaviour that is documented and intended, or that requires a setting the operator has deliberately enabled, unless you can show it is exploitable in a default or reasonably expected configuration.
- The fact that an instrument control protocol such as SCPI is unauthenticated by design on a segmented test network, absent a demonstrated way to reach it from somewhere it should not be reachable.
- Attacks that require the attacker to already have physical possession of an instrument they are free to dismantle, with no path to remote or in line exploitation.
- Denial of service, volumetric, load or stress testing of any kind.
- Social engineering, phishing, or physical intrusion against employees, customers, offices or facilities.
- Vulnerabilities in third party chassis, host controllers, operating systems, probers, handlers, instruments or manufacturing execution systems that we do not control. Report those to the relevant vendor, and tell us if a Quantifi Photonics product is affected as a result.
- Discontinued products and software releases that have reached end of support, unless the issue also affects a supported release.
- Reports that consist only of a version number matched against a public CVE list, with no analysis of whether the affected code path is reachable in our product.
Before you test
Rules of engagement
Our instruments are high value test and measurement equipment, and they are often the single point of test on a manufacturing line. Please observe the following.
Never test against an instrument in productive use
Do not test on any system that is running a live production or qualification workload. Taking an instrument down or corrupting its calibration can halt a customer’s manufacturing line and invalidate results already produced.
- Test only on equipment you own, or for which you have the documented, explicit permission of the owner. Never test on a Quantifi Photonics customer’s equipment.
- Keep test systems on an isolated network segment, separate from any production or corporate network.
- Stay within scope. Do not pivot to other systems, networks or accounts.
- Use only the minimum access needed to demonstrate the issue. Stop as soon as you have proven it, and do not attempt to escalate further.
- Do not access, copy, modify or destroy data that is not yours. Test results, calibration data and test plans can reveal a customer’s unreleased product designs, so if you encounter data of this kind, or personal data or credentials, stop immediately, do not retain a copy, and tell us in your report.
- Do not degrade, interrupt or damage any service, system or piece of equipment, and do not alter calibration data on a system you do not own.
- Report the issue to us promptly after discovery, and give us a reasonable opportunity to remediate before disclosing it publicly.
- Keep the details confidential between you and us until we have jointly agreed that it is appropriate to publish.
- Do not use your findings, or the fact of your access, to demand payment. Reports submitted with a payment demand attached are handled as extortion, not research.
Legal position
Safe harbour
If you make a good faith effort to comply with this policy during your research, we will consider your activity authorised. We will not initiate or support legal action against you, or refer you to law enforcement, in connection with research conducted in accordance with this policy. If a third party brings legal action against you for research that complied with this policy, we will make that compliance known.
This policy does not give you permission to act on any network or system belonging to a third party, including our customers and suppliers, and it does not waive any obligation you have under applicable law. If you are unsure whether something you plan to do is permitted, ask us first through the form before you do it.
Preparing your submission
What to include in your report
The intake form walks you through six short sections. The more precise you are, the faster we can reproduce the issue and route it to the engineers who own the affected code. Please have the following ready.
01 / You
About you
Your name or handle, and an email address we can reply to. An organisation name is optional, and so is a PGP public key if you would like our follow up encrypted.
02 / Product
Affected product
The instrument model or software affected, the exact firmware or software version and build, the system controller OS version, and the interface, port or URL where you found the issue. This determines which engineering team receives your report.
03 / Flaw
The vulnerability
The vulnerability class, a CVE identifier if one already exists, and a technical description of the flaw: the vulnerable component, the root cause, and the conditions under which it triggers.
04 / Proof
Proof and reproduction
Numbered, self contained steps that let an engineer reproduce the issue on a clean system, plus any proof of concept request, payload, script or instrument command sequence involved.
05 / Impact
Impact
What an attacker gains, and be explicit if it includes falsifying test results, altering calibration, or reaching customer test data. Also what they need first: network position, a valid account, administrative rights, physical access.
06 / Exposure
Exposure and disclosure
Whether you have seen the issue being exploited, whether any part of it is already public, any disclosure deadline you are working to, and anything else we should know.
Files
Attachments
You can attach supporting evidence: screenshots, logs, packet captures, crash dumps, or proof of concept code. The form accepts .txt .py .js .html .pdf .png .jpg .jpeg .gif .pcap .cap .zip .tar and .gz files. Every attachment is scanned for malware on arrival. Please redact any third party personal data before you upload, and never include live customer data, test results or calibration data belonging to a customer.
Our process
What happens after you submit
You get a Tracking ID
As soon as your report is received you get an automated confirmation email with a Tracking ID. Quote it in any follow up so we can find your report instantly.
We triage and route it
Your report is assessed for severity and regulatory significance, then routed to the Quantifi Photonics product security and engineering team, where a named contact picks it up.
We validate and rate it
Our engineers attempt to reproduce the issue and assign a severity using CVSS. We will come back to you if we need more detail, and we will tell you the outcome of the assessment, including if we conclude it is not a vulnerability, and why.
We remediate
Confirmed issues are tracked to a fix in our engineering systems. Timelines depend on severity and on the release and qualification cycle of the affected product, and a fix for production test equipment must be validated before it ships. We will keep you updated on progress.
We disclose together
Where appropriate we publish an advisory and, if applicable, request a CVE identifier. We coordinate timing with you and credit you as you prefer. If we are required to notify a regulator or a national CSIRT, we will do so and let you know.
Routing
If this is not a product vulnerability
Please use the right channel so your issue reaches the right people. This process is only for suspected security vulnerabilities.
- A non-security product fault, a measurement question, or you need help with a product: contact Quantifi Photonics support through your usual support channel.
- Calibration, repair or warranty: use the calibration and repairs and warranties pages.
- A commercial, sales or general enquiry: use contact us or request a quote.
- You believe one of your own Quantifi Photonics instruments has been compromised: disconnect it from the network, stop using it for production or qualification measurement, and contact your Quantifi Photonics support representative immediately, telling them you believe it is a security incident.
- A phishing email, or a website impersonating Quantifi Photonics: report it through the form and select information disclosure or security misconfiguration. Do not interact with the message further.
Quantifi Photonics is a Teradyne company. If your finding affects another Teradyne brand, whether Teradyne test systems, LitePoint, Universal Robots or Mobile Industrial Robots, you can submit it through the same form and it will be routed to the right team.
Submit
Ready to report?
The form takes about ten minutes if you have your reproduction steps and evidence to hand. It is submitted over an encrypted connection directly to our product security team.
psirt.teradyne.com · encrypted intake · no account required
By submitting a report you confirm that you have read and will follow this policy, and you agree that we may use the information you provide to investigate and remediate the issue, and to notify affected customers, partners and regulators as required. Your report is handled confidentially by our product security team.
We do not operate a paid bug bounty programme and do not offer monetary rewards for vulnerability reports.
Quantifi Photonics Coordinated Vulnerability Disclosure policy. Effective 26 August 2026. We may update this policy; the version published here at the time you begin your research is the one that applies.