Third Party Index

Snapshot 46512

Document
Trust center
URL
https://trustcenter.dotmatics.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
1079546 bytes
SHA-256 (raw)
9078b85589a312ddba5996d7c87fbc5f3722c701afeebc21bbe50806e8f08a90
SHA-256 (normalized text)
968073bfdf1c1736f248a0332a0404053a5bd76d3097d1e0015f7c586a94da0c

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Start your security review
View & download sensitive information
GraphPad Prism
Welcome to the Dotmatics Trust Center for GraphPad including the products Prism and Prism Cloud. In this portal, you will find artefacts and information intended to help customers and partners understand this products' security, privacy, quality, and compliance posture.
Compliance
CCPA
CPRA
GDPR
ISO/IEC 27001 SoA
ISO/IEC 27001:2022
PCI DSS
Documents
COMPLIANCEISO/IEC 27001 SoA
COMPLIANCEISO/IEC 27001:2022
SELF-ASSESSMENTSHECVAT Lite
APP SECURITYUS Secure Software Development Attestation
LEGALData Privacy Terms
ESGAnti-Modern Slavery (UK)
Risk Profile
Data Access Level
Impact Level
Recovery Time Objective
View more
Product Security
Data Security
Multi-Factor Authentication
SSO Support
Reports
Self-Assessments
HECVAT Lite
Data Security
Customer Data Isolation Controls
Data Backups
Data Erasure
View more
App Security
Code Analysis
Software Development Lifecycle
Vulnerability & Patch Management
View more
AI
ESG
Anti-Modern Slavery (UK)
Whistleblowing Program
Legal
Subprocessors
Data Privacy Terms
Data Processing Agreement
View more
Data Privacy
Cookies
Data Privacy
Data Protection Officer
View more
Access Control
Data Access
Internal Single-Sign-On (SSO)
Password Security
Infrastructure
Sensitive Workload Isolation and Network Security in AWS
Amazon Web Services
Separate Production Environment
View more
Endpoint Security
Disk Encryption
Endpoint Detection & Response
Mobile Device Management
Network Security
Load Balancer Security and Traffic Control
Network Access Control
Network Traffic Monitoring
View more
Corporate Security
Asset Management Practices
Email Protection
Employee Handbook
View more
Policies
Information Security Policy
Security Grades
Incident Response and Monitoring
Incident Response and Monitoring
BC/DR
Business Continuity Management System (BCMS)
Physical & Environment
Alarms & Surveillance
Data Center
Emergency Power & Lighting
View more
Knowledge Base (FAQ)
Trust Center Updates
Customer Security Advisory: CVE-2025-55182 and CVE-2025-66478
Vulnerabilities
Date: 5 December 2025
Dotmatics is providing this update to inform our customers of our investigation and response to two notable and recently disclosed vulnerabilities in the JavaScript ecosystem: CVE-2025-55182 and CVE-2025-66478.
1. CVE-2025-55182 React Server Components
On 3 December 2025 at approximately 4:12 PM ET, we became aware of a publicly disclosed vulnerability affecting certain React server-side packages (CVE-2025-55182). Reference materials are available here:
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
https://nvd.nist.gov/vuln/detail/CVE-2025-55182
Immediately upon becoming aware of this disclosure, we initiated an internal review to evaluate whether any products within our application portfolio incorporate the affected React server-side components.
This review was completed at approximately 6:21 PM ET on 3 December 2025. Based on that assessment, no products within our portfolio were found to use the React server-side components associated with CVE-2025-55182.
2. CVE-2025-66478 Next.js (downstream impact)
At approximately 10:51 PM ET on 3 December 2025, we became aware of CVE-2025-66478 which is a downstream vulnerability impacting Next.js due to its dependency on the components associated with CVE-2025-55182. Reference materials are available here:
https://nextjs.org/blog/CVE-2025-66478
https://nvd.nist.gov/vuln/detail/CVE-2025-66478
Immediately upon becoming aware of this disclosure, we initiated an internal review to evaluate whether any products within our application portfolio incorporate the affected Next.js components.
During our review, we identified that two products in our application portfolio: Luma and Sigma components, used affected Next.js versions.
Remediation
Upon identification of these affected components, we immediately initiated our standard vulnerability response procedures, including patch application, internal testing, quality verification, and deployment. All remediation activities were completed by 4 December 2025.
Our monitoring to date has not identified any indicators of abnormal, anomalous, or unauthorized activity associated with these vulnerabilities in the context of our products or environments.
We note that vulnerabilities of this nature may evolve as additional security research becomes available. Accordingly, we will continue to monitor for updates and will take further action as necessary.
3. Customer Guidance
No customer action is required at this time with respect to our products that incorporated the affected Next.js components. If new information becomes available that changes required customer actions or materially impacts risk, we will issue updated communication.
For questions or additional information, please contact your account representative.
Dotmatics Not Affected By MoveIT Vulnerabilities
Vulnerabilities
There have been many first hand and media reports regarding a high risk, high impact vulnerability in MOVEit file transfer software leading to compromise and ransomware attacks across multiple industries. A recent update from CISA can be found here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a
Dotmatics has done a review of implemented software across the organisation and can confirm that we do not run this software, and are not impacted by this vulnerability.
Welcome to the Dotmatics Trust Center
General
Welcome to Dotmatics' Trust Center. We are pleased to announce the launch of our customer-facing, self-service home for documents and answers on security, privacy, and compliance matters. We will also use this Trust Center as a place to provide confirmed information to customers when it's critical that you know the origin is authentic.
If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue