Security at GDS Instruments
Our soil and rock mechanics testing systems ship with control software and instrument firmware. This is how we build, test and maintain that software, how long we support it, and how to reach us if you find a problem.
-
Report a vulnerability
Found a security issue in GDSLAB or an instrument controller? Our coordinated disclosure policy sets out how to reach us, what to include, and the timelines you can expect from us.
Read the disclosure policy → -
Security advisories
Published advisories for vulnerabilities we have fixed, with affected versions, severity and the steps needed to remediate. Available as an Atom feed.
View advisories → -
Product support periods
How long each product family receives security updates, when support ends, and how long we keep past updates available for download.
Check your product →
Cyber Resilience Act readiness
Regulation (EU) 2024/2847 applies to products with digital elements placed on the EU market. Our control software and instrument firmware fall within its scope, which makes GDS a manufacturer under the Regulation. Our obligations phase in as follows.
- In force 11 June 2026 Chapter IV applied — notification of conformity assessment bodies. No direct GDS action required.
- In force now 11 September 2026 Article 14 reporting applies. Actively exploited vulnerabilities and severe incidents must be reported to ENISA and our designated national CSIRT: early warning within 24 hours, notification within 72 hours, final report within 14 days.
- Planned 11 December 2027 Full essential cybersecurity requirements — Annex I, conformity assessment, CE marking and technical documentation.
Read our full CRA statement, including which products are in scope and our conformity approach.
Explore the trust centre
-
Secure development
How we test our software, sign our updates, and ship products that are secure in their default configuration.
-
Software transparency
The third-party components in our software, the SBOM formats we produce, and how to request one for your system.
-
Certifications
The management system certifications GDS holds today, and what we are working towards.
-
Data protection
What personal data our products and services handle, and how we meet UK GDPR and the Data Protection Act 2018.
-
Supplier security
How we assess the security of the components, embedded software and services we build into our systems.
-
Cyber Resilience Act
Products in scope, our reporting route, the support periods we commit to, and our conformity assessment approach.
Reaching our security team
Security reports go to a monitored mailbox, not to an individual. Please do not send vulnerability details to sales or general support contacts, as they are not routed to the security team.
- security@gdsinstruments.com
- PGP key
- Download public key
- Fingerprint
E3B8 F5F4 863E 2A84 2F32 25CD B168 9DFA 3431 7991- Machine-readable
- /.well-known/security.txt
- Acknowledgement
- Within 3 working days
- Post
- Security Team, Global Digital Systems Ltd, Unit 32 Murrell Green Business Park, London Road, Hook, Hampshire RG27 9GR, United Kingdom
If you believe a vulnerability is being actively exploited
Say so in the subject line and mark the message urgent. Active exploitation starts a 24-hour reporting clock for us under Article 14 of the Cyber Resilience Act, so we need to triage it immediately.