If you believe you've found a security vulnerability in a Blue Goat Cyber service - or in a medical device we support - we want to hear from you.
Use this secure form to send the basics of your finding. For sensitive technical details, email cvd@bluegoatcyber.com - we'll reply with a PGP key on request.
Please give us a reasonable time to investigate and remediate before disclosing publicly. Avoid privacy violations, service degradation, and destructive testing. Do not access or modify data belonging to others.
We will coordinate with the device manufacturer and, where applicable, the FDA and CISA under accepted CVD practices.
Email our CVD teamGenerate a §524B-aligned disclosure policy, then size your postmarket monitoring cadence.
Coordinated Vulnerability Disclosure is one piece of a full postmarket cybersecurity program. We help manufacturers stand the rest up.
Vulnerability monitoring, CVD intake, patch validation, and FDA reporting workflows.
Read Postmarket cybersecurity servicesSPDX/CycloneDX SBOMs with continuous CVE/KEV mapping - the foundation of any CVD program.
Read FDA-compliant SBOMsManaging security for deployed devices that pre-date current FDA guidance.
Read Legacy medical device cybersecurityIndependent testing to find issues before researchers report them through CVD.
Read Medical device penetration testingDocumented threat models that make incoming CVD reports faster to triage.
Read Threat modelingSDVOSB medical device cybersecurity firm - 275+.
Read About Blue Goat Cyber30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ devices supported.