Back to Landing page

Dexcom’s Commitment to Product Security

Policy Statement

We value patient safety and we strive to provide products that are safe and effective for our patients to use in the management of their diabetes.
As digital health advances, so do the risks. While no program can guarantee perfect security, we strive to make cybersecurity an essential part of our overall safety, quality, and privacy strategy.
Dexcom regularly evaluates our systems for potential risks and vulnerabilities. To protect the integrity and availability of our products and services, we employ robust security controls designed to limit access to authorized users and trusted applications. These safeguards aim to support secure data handling, consistent system performance, and the protection of the trust placed in us by patients, caregivers, clinicians, and partners.
Select the Coordinated Vulnerability Disclosure link to responsibly report a potential security vulnerability to Dexcom’s security team.
Select the Security Advisories link to review security best practices and guidance for Dexcom products and services.

Product Security Program at Dexcom

Dexcom’s Product Security program is responsible for the confidentiality, integrity, availability, privacy, and safety of our products by embedding security principles in the product lifecycle; from design through post-market operations.
We work cross-functionally across engineering, regulatory, quality, and commercial teams, together seeking to deliver more secure, compliant, and trustworthy products for patients, providers, and partners worldwide. Our Product Security is designed to focus on the following core areas.

Core Areas & Functions

  1. Secure Product Design & Architecture
    • Define and enforce more secure system architecture.
    • Embed security into product development processes.
    • Manage product security risks and regulatory alignment.
  2. Engineering Security & Developer Enablement
    • Build and maintain security tools to support development teams.
    • Better secure mobile applications and product software.
    • Enable secure-by-design and secure coding practices in R&D.
  3. Cryptography & Key Management (PKI)
    • Better manage certificate of lifecycle and device identity.
    • Support more secure communication across devices, APIs, and platforms.
    • Operate foundational cryptographic services for product ecosystems
  4. Offensive Security & Testing
    • Conduct penetration testing across the web, mobile, cloud, firmware, and hardware.
    • Identify vulnerabilities and provide remediation guidance.
    • Regularly validate product security posture.
  5. Security Operations & Monitoring
    • Detect and respond to threats across product environments.
    • Manage vulnerabilities and security events.
    • Enable continual monitoring to protect product infrastructure.
  6. Governance, Risk & Compliance (GRC)
    • Provide cybersecurity governance and regulatory support.
    • Perform risk assessments and comply with applicable international standards.
    • Produce audit-ready security evidence for regulators, customers, and partners.
  7. Product Security Lifecycle & Release Assurance (CSPO)
    • Strengthen ability of products to meet security requirements before release.
    • Integrate security into development workflows.
    • Coordinate across teams to drive consistent security outcomes

Core Areas & Functions

  1. Secure Product Design & Architecture
    • Define and enforce more secure system architecture.
    • Embed security into product development processes.
    • Manage product security risks and regulatory alignment.
  2. Engineering Security & Developer Enablement
    • Build and maintain security tools to support development teams.
    • Better secure mobile applications and product software.
    • Enable secure-by-design and secure coding practices in R&D.
  3. Cryptography & Key Management (PKI)
    • Better manage certificate of lifecycle and device identity.
    • Support more secure communication across devices, APIs, and platforms.
    • Operate foundational cryptographic services for product ecosystems
  4. Offensive Security & Testing
    • Conduct penetration testing across the web, mobile, cloud, firmware, and hardware.
    • Identify vulnerabilities and provide remediation guidance.
    • Regularly validate product security posture.
  5. Security Operations & Monitoring
    • Detect and respond to threats across product environments.
    • Manage vulnerabilities and security events.
    • Enable continual monitoring to protect product infrastructure.
  6. Governance, Risk & Compliance (GRC)
    • Provide cybersecurity governance and regulatory support.
    • Perform risk assessments and comply with applicable international standards.
    • Produce audit-ready security evidence for regulators, customers, and partners.
  7. Product Security Lifecycle & Release Assurance (CSPO)
    • Strengthen ability of products to meet security requirements before release.
    • Integrate security into development workflows.
    • Coordinate across teams to drive consistent security outcomes

End-to-End Impact

Across these functions, our Product Security program is designed to enable:
  • More secure product development and delivery at scale.
  • Regulatory readiness and global market access.
  • Ongoing risk management and post-market security operations.
  • Trust and transparency with customers and regulators.

Navigating this Site

Select the Security Advisories link to Dexcom’s latest security advisories.
Select the Security Practices link to review security best practices and guidance for Dexcom products and services.
Select the Coordinated Vulnerability Disclosure link to responsibly report a potential security vulnerability to Dexcom’s security team.
Select the Dexcom Trust Center link to review Dexcom’s enterprise-wide security status and information about our privacy and compliance programs.
Privacy PolicyTerms of Use

MAT-5161

© 2026 Dexcom, Inc. All rights reserved.

US flag

US