Responsible Disclosure
We appreciate your help in reporting bugs and have set up a program to allow our security researchers to report bugs. Please reach out to security@biorender.com or visit our bug bounty program: https://www.federacy.com/biorender?tab=Intro
Code Analysis
In order to ensure the security and dependability of our digital solutions, we at BioRender have taken proactive steps to build a strong app security policy. Our program consists of:
Visibility: We place a high value on transparency inside our software components, giving details on all of our procedures and equipment.
Automation: Realizing the importance of efficiency, we have utilized automation for critical security operations like vulnerability scanning and the effective management of security tools.
Risk insights: Our method produces crucial information about potential risks that helps security decisions be made with knowledge.
We have implemented a number of steps as evidence of our steadfast dedication to security, including:
CI/CD security posture: We keep a close eye on security across the whole development pipeline, enabling our DevSecOps and security teams to address possible cyber attacks before they happen.
Marketplace for security tools: We have created a platform that allows for the seamless integration of both open-source and paid security tools.
SCA, or software composition analysis: Our program scans each of our software's components, identifying vulnerabilities and providing detailed information on their type, seriousness, and potential effects.
Secret data management and detection: We keep a close eye on passwords, API keys, and other important credentials included within our software code.
Security for containers: We routinely check our container images for flaws and take corrective action when necessary.
DevSecOps consulting: In order to improve our software security posture, we continuously improve our DevSecOps procedures.
Credential Management
We manage all secrets using the AWS Key Management Service and rotate keys.
Vulnerability & Patch Management
We install all patches and software updates as soon as they are made available. All vulnerabilities are tracked in our vulnerability management database.
Was this article helpful?
Articles in this section
- App security
- Data handling & security controls for BioRender Graphing
- Compliance documents (SOC 2 Type 2, VPAT, SOC 3)
- BioRender's data policies
- Data privacy & security at BioRender
- BioRender's AI security controls
- Infrastructure at BioRender: BioRender AWS hosting
- Access control
- BioRender's employee training policy
- BioRender's endpoint security