MESCIUS Product Security Overview
MESCIUS provides components that help developers build applications, services, and systems that meet their business and technical requirements. MESCIUS applies secure development, software supply chain management, release integrity, and vulnerability handling practices to reduce risk within the components it delivers.
- Shared Security Model
- Data Processing and Privacy
- Secure Development Process
- Code Review and Engineering Controls
- Security Testing
- Third-Party Components and Supply Chain
- Release Integrity
- Vulnerability Management
- Vulnerability Resolution Timeline
- Incident ResponseCustomer Security Information
- Further Information
This overview supports customers evaluating MESCIUS components for procurement, compliance review, risk assessment, or software supply chain due diligence. It addresses common security questions and summarizes practices used across ComponentOne, ActiveReports.NET , ActiveReportsJS, Spread.NET, SpreadJS, Document Solutions, and Wijmo.
MESCIUS maintains a common framework of security practices across its product portfolio. The scope and implementation details of individual practices may vary by product, platform, and release channel. MESCIUS may provide product-specific information based on the applicable product, version, support status, and scope of the customer request.
Shared Security Model
Security for solutions built with MESCIUS components follows a shared responsibility model, in which MESCIUS and its customers are responsible for different parts of the overall solution. MESCIUS applies secure development, validation, release, and vulnerability management practices to the components it provides. Customers manage the security of the final application, service, or system in which those components are used.
MESCIUS components form one part of the customer's solution. Application architecture, authentication and authorization rules, data sources, network boundaries, hosting configuration, and operational controls are defined and managed within the customer's overall application environment.
This distinction is important when evaluating enterprise application or SaaS security questionnaires: some controls apply directly to MESCIUS components, while others apply to the final application and deployment environment. MESCIUS provides product documentation and secure integration guidance to help customers use MESCIUS components within their own security model.
Data Processing and Privacy
In the standard component-use model, MESCIUS components run within the customer's application, service, or environment and process data supplied by that application. Once integrated and deployed, MESCIUS components do not transmit customer application data to MESCIUS systems.
JavaScript products do not use a license activation mechanism and do not transmit data to MESCIUS systems as part of product operation. For certain .NET developer products, license activation transmits limited technical metadata, such as the operating system version and IP address, solely for license validation and identification of the activated device.
ComponentOne installers and ComponentOne components used at design time in Visual Studio may collect limited, anonymous product usage information, such as which components are used. Users can opt out of this collection during ComponentOne installation. Neither license activation nor this product usage collection transmits customer application data, end-user content, sensitive business information, or user-provided contact details such as names or email addresses.
Customers control what data is provided to a component, how that data is protected, and where their application stores or transmits it. Data security and privacy therefore also depend on the customer's application architecture, data handling logic, hosting environment, and operational controls.
Information provided or transmitted when customers use MESCIUS websites and account systems, download products, activate or manage licenses, or engage support or professional services is separate from customer application data. This information is handled under the applicable MESCIUS privacy, support, and service terms.
Secure Development Process
MESCIUS incorporates security into a structured product lifecycle spanning planning, design, development, testing, release, and post-release maintenance. The practices described below are applied according to each product's architecture, technology stack, and risk profile.
MESCIUS secure development practices include:
- established standards and best practices for secure coding
- design and security review during feature planning, including security requirements, risk, and threat considerations
- peer review of code changes before they are merged
- protected source branches and controlled release workflows
- automated and manual validation appropriate to each product
- dependency review and vulnerability scanning, with coverage appropriate to each product
- release checks before product delivery
- severity-based handling of security issues
- post-release monitoring and maintenance updates
For security-sensitive features, teams review the relevant attack surface, expected data flow, trust boundaries, dependency impact, and misuse scenarios before implementation or release. The depth of review reflects the product architecture and feature risk.
Code Review and Engineering Controls
MESCIUS requires code changes to be reviewed before they are merged and released. Reviewers evaluate correctness, maintainability, performance, compatibility, test coverage, and security impact.
Teams use static analysis, secure coding checks, linting, dependency scanning, and other automated checks during development and build validation. The specific tools and coverage vary by product and technology stack. These checks help identify common coding errors, vulnerable dependency versions, unsafe patterns, and regressions before release.
Representative tools and practices include SonarQube for static application security testing, Microsoft .NET analyzers and Roslyn-based code analysis for .NET products, and ESLint security rules for JavaScript and TypeScript products. MESCIUS also uses secrets scanning in relevant repositories and release workflows to help detect accidentally committed credentials or sensitive values.
Development and build environments for .NET products use supported versions of Visual Studio and the .NET SDK, with applicable security updates incorporated as part of ongoing toolchain maintenance.
Security-sensitive changes receive additional attention, especially where user input, file processing, document rendering, browser execution, authentication, authorization, or data handling are involved.
Security Testing
MESCIUS tests normal product behavior and security-relevant edge cases through feature, regression, integration, performance, compatibility, and release testing. The scope reflects the product architecture, feature risk, and release type.
For browser-based products such as SpreadJS, ActiveReportsJS, and Wijmo, validation covers areas such as cross-site scripting (XSS) prevention, safe content rendering, and Content Security Policy compatibility. For reporting, document-processing, and server-side scenarios, validation covers input handling, file processing, resource constraints, and error handling.
When a security issue is identified and fixed, MESCIUS adds regression coverage where applicable to reduce the risk of the issue recurring in a future release.
Third-Party Components and Supply Chain
Third-party components and open-source packages are an important part of software supply chain security. MESCIUS product teams review dependencies for license compatibility, maintenance activity, known vulnerabilities, and product impact.
MESCIUS uses dependency scanning and vulnerability intelligence to identify known issues in third-party packages, with coverage based on each product's technology stack. Findings are reviewed based on severity, exploitability, affected product versions, and realistic customer impact.
Representative dependency and vulnerability checks include NuGet Audit for .NET dependencies, npm audit for JavaScript packages, OWASP Dependency-Check for relevant package types, and vulnerability intelligence from sources such as GitHub Advisories, package-manager advisories, vendor notices, and public vulnerability databases.
MESCIUS maintains third-party notices or open-source disclosure information for applicable products. Customers can contact MESCIUS to request currently available product-specific SBOM information. MESCIUS is expanding this capability across the portfolio, with the goal of including SBOM information as a standard part of applicable product release packages.
Release Integrity
MESCIUS uses controlled processes to review, validate, and deliver product releases through approved channels.
Depending on the product and distribution format, release integrity measures include:
- controlled build and release pipelines
- digital signing of supported binary artifacts using protected signing credentials
- package validation before publication
- checksum or integrity information for applicable package types
- release notes describing important product changes, including security fixes when relevant
MESCIUS selects integrity controls according to the product type, platform, package ecosystem, and distribution channel.
Vulnerability Management
MESCIUS evaluates security issues reported by customers, identified internally, discovered through dependency monitoring, or published by third-party vendors and security advisories.
Reported or discovered issues are reviewed to determine:
- whether the product is affected
- which versions are affected
- how the issue could be exploited
- whether customer systems are realistically impacted
- what mitigation or fix is appropriate
- whether customer communication is needed
MESCIUS uses CVSS as a reference when assessing vulnerability severity, together with exploitability, affected product scope, realistic customer impact, and available mitigations.
Based on this assessment, MESCIUS prioritizes vulnerabilities and determines the appropriate remediation. Remediation can take the form of a hotfix, maintenance release, service pack, scheduled release fix, mitigation guidance, or security advisory.
Vulnerability Resolution Timeline
MESCIUS uses the following severity-based targets for initial response and remediation. Actual delivery depends on product architecture, affected versions, exploitability, validation scope, release channel, and hotfix requirements.
| Severity | Initial response target | Remediation target |
|---|---|---|
| Critical | 1 business day | Hotfix or mitigation target of 2-4 business days |
| High | 2-3 business days | Target resolution within 15 days |
| Medium | 5 business days | Target resolution in the next applicable release |
| Low | Next planning cycle | Target resolution in the next major release or regular maintenance cycle |
For Critical or High vulnerabilities that could realistically affect customers, MESCIUS shares remediation information with the relevant product, support, and customer-facing teams. This information includes the affected product and versions, severity, customer impact, available mitigations, expected remediation timeline, and a CVE or advisory reference when available.
When customer action or awareness is required, MESCIUS communicates security fixes and guidance through channels appropriate to the product and situation, including release notes, product support channels, direct customer communication, mitigation guidance, and security advisories.
Incident Response
MESCIUS maintains an incident response process for urgent security events, such as confirmed exploitation, serious security exposure reported by a customer, leaked credentials affecting release or build systems, or concerns about release artifact integrity.
The process includes:
- detection and intake
- triage and severity assessment
- impact analysis
- remediation or mitigation planning
- customer or stakeholder communication when needed
- post-incident review when needed
For serious issues, MESCIUS coordinates engineering, product management, support, and other stakeholders to determine customer impact and the appropriate response.
Customer Security Information
Customers can request product-specific security information for procurement, risk review, compliance assessment, or internal security approval. Depending on the product and request scope, MESCIUS may provide:
- a high-level secure development overview
- third-party component or open-source disclosure information
- release notes for security fixes or security-relevant changes
- vulnerability handling information
- product-specific secure configuration or integration guidance
- available SBOM or related supply chain information upon request and, as availability expands, as part of applicable release packages
Detailed development procedures, internal test plans, threat models, build infrastructure details, and incident records remain internal. MESCIUS provides customer-facing security information at a level appropriate to the product, request scope, and approval process.
Further Information
Customers who need additional product-specific security information can contact MESCIUS Support or their MESCIUS account representative. MESCIUS will review the request and provide available information based on the applicable product, version, release channel, and approval path.
Customers who need deeper implementation guidance can also engage MESCIUS professional services for tailored technical support, project-level review, or implementation recommendations where available.