On this page: Coordinated Vulnerability Disclosure | Bulletins | Patches | Documentation
Protecting the integrity, confidentiality, and security is essential to ensuring product safety and reliability. This section provides security-related information, including bulletins, patches, and documentation, to help customers and partners understand and address potential risks.
On this page: Coordinated Vulnerability Disclosure | Bulletins | Patches | Documentation
As software and technology continue to become more integrated in our products, Illumina recognizes cybersecurity to be an important element in managing risk across the total product lifecycle. Cybersecurity threats are evolving, and they have the potential to not only impact the confidentiality, integrity, and availability of a product, but also its effectiveness in its intended use.
Illumina maintains a dedicated Product Security team responsible for evaluating and implementing security controls, managing cybersecurity risk across our various product lines, and executing our cybersecurity post-market product surveillance and support program.
We recognize and appreciate the value provided by our customers and security researchers in identifying cybersecurity risks on Illumina’s products and look forward to collaborating with those partners in good faith.
The scope of the Illumina Coordinated Vulnerability Disclosure Program includes on-market products and associated SaaS applications (e.g. BaseSpace Sequence Hub, Illumina Connected Analytics, Illumina Connected Insights, Correlation Engine, ClarityLIMS, Emedgene). Infrastructure and software owned and used by Illumina in operating its business are out of scope of this Coordinated Vulnerability Disclosure Program. Additionally, the Coordinated Vulnerability Disclosure Program should not be used for submitting adverse events or product quality complaints. Please follow the appropriate processes laid out by the individual product lines for reporting these types of issues.
As a part of our Coordinated Vulnerability Disclosure Program, Illumina will be using this page to post cybersecurity bulletins related to vulnerabilities and their potential impact to Illumina products. For any additional questions or comments related to product security at Illumina, please contact your service representative and/or the product security team.
How to contact Illumina Product Security:
Upon identifying a potential vulnerability in an Illumina product, please contact the Product Security team via email as soon as possible using Pretty Good Privacy (PGP) encryption as follows:
In the email, please provide all relevant technical information regarding the vulnerability, including, but not limited to:
Do not include any personally identifiable information (PII) or individually identifiable health information (IIHI) in the message.
For any research being conducted on Illumina products, we ask researchers to:
After receiving notice of a potential vulnerability, Illumina will:
If you share any information with Illumina, you agree that the information you submit will be considered as non-proprietary and non-confidential, and that Illumina is allowed to use such information in good faith, in any manner, in whole or in part, and without any restriction.
Stay informed with the latest product security bulletins. This section provides timely updates on identified vulnerabilities, their impact, and recommended mitigations to help you safeguard your systems.
Access critical security patches and updates for our products. We will provide information regarding patch releases, installation instructions (where appropriate to do so), and product security best practices to assist customers with ensuring their software remains secure and up-to-date.
Find comprehensive product security documentation, including best practices, configuration guides, and security architecture overviews. This section serves as a resource for administrators and customers’ technical support for additional information about recommended security measures.
If you identify a potential vulnerability in an Illumina product, please contact us via email as soon as possible utilizing PGP (Pretty Good Privacy encryption program) as outlined below:
Key ID: B286E33E2CCD79B5
PGP Location: https://keys.openpgp.org/