Security throughout the device lifecycle
Inventus is committed to protecting the security of its purpose-built clinical trial devices throughout their lifecycle.
Our devices are supported through controlled software configuration, centralised device management and ongoing security updates. This page explains our device security support, how to report a potential vulnerability and how Inventus responds to reported issues.
Information security & data protection
Inventus takes a comprehensive approach to information security across our products, systems and operations.
Inventus maintains ISO 27001 certification for its Information Security Management System in China and Austria, supporting a structured approach to managing information security risks. We are also registered with the UK Information Commissioner’s Office (ICO), the UK’s independent regulator for data protection and information rights.
Security update commitment
Inventus is committed to providing security updates for its devices throughout their defined support period.
Security updates will be provided for a minimum of five years, with longer support periods where applicable based on the expected product lifecycle. The minimum security support period and end date for each Inventus device will be clearly published on this page.
Device security support
Inventus provides routine and emergency security support for its CT1 patient device and CT7 site device.
CT1 Patient Device
Routine security support: Until October 2027
Emergency security support: Until October 2028
CT7 Site Device
Routine security support: Until October 2027
Emergency security support: Until October 2028
Report a security vulnerability
Customers, partners and security researchers can report potential vulnerabilities affecting Inventus devices, software or device-management services.
Email: security@invent-us.com
Please include the affected product, a description of the issue, its potential impact and any relevant technical information.
Please do not include patient, clinical-trial or other sensitive personal information.
What you can expect
Inventus will acknowledge receipt of the report and assess the information provided.
We aim to acknowledge vulnerability reports within two business days and will provide updates as the investigation progresses.
Resolution times will depend on the severity, complexity and scope of the issue.
Vulnerability response and disclosure process
Inventus follows a structured process to assess, manage and respond to reported security vulnerabilities, from initial triage through to remediation and communication.
1. Intake & Triage
We receive, review and assign reported vulnerabilities for investigation.
2. Validation & Assessment
We confirm the vulnerability and assess its severity, exploitability and potential impact.
3. Impact & Scope Analysis
We identify the affected products, software versions, services and potential customer exposure.
4. Mitigation Development
We develop and validate appropriate fixes, remediation actions or risk mitigations.
5. Security Advisory Release
Where required, we publish security guidance, mitigation details and relevant customer communications