EVIDENT Coordinated Vulnerability Disclosure (CVD) Policy and Product Security Statement
Introduction
EVIDENT takes cybersecurity and product security very seriously. We are committed to ensuring the safety of our users and patients, protecting the confidentiality of their data, and maintaining the security of our products and services with digital elements.
To professionally deal with any threats related to the ever-expanding and highly complex field of cybersecurity, we have created a product security team with dedicated professionals who are continuously working on important topics such as risk assessment, threat modeling, secure design, secure coding and an overall secure development lifecycle (SDLC) of our products.
Vulnerability reporting and disclosure are essential pillars of our cybersecurity posture as well.
We provide this Coordinated Vulnerability Disclosure (CVD) policy to support responsible reporting and resolution of security vulnerabilities.
Where regulatory obligations differ by jurisdiction, EVIDENT will apply the relevant legal framework applicable to the affected product and market.
Scope
This CVD policy applies to:
- All software and hardware products with digital elements offered by EVIDENT, we encourage responsible disclosure of vulnerabilities or incidents for all our products with digital elements.
- Any associated remote data processing solutions required for product functionality.
How to Report a Vulnerability
EVIDENT provides a public and easy-to-access vulnerability intake channel to support expectations for discoverability, optional anonymous reporting and structured intake. This CVD policy supports public vulnerability intake and coordination with reporters, but does not replace, limit or define EVIDENT’s separate regulatory reporting obligations under the CRA or other applicable laws to CSIRTs, ENISA, market surveillance authorities or other competent bodies, where applicable.
You can submit a vulnerability via email: product.security.reporting@evidentscientific.com.
If possible, please provide the vulnerability report in English to expedite the analysis of your report.
The following information to the extent reasonably possible is required to submit a vulnerability:
- A short summary of the vulnerability
- A detailed description of the vulnerability
- Potential impact of the vulnerability
- Affected product(s) and version(s)
- If applicable, configuration details, such as the system hardware setup (variant), connected hardware devices for the setup in question, operating system, network connection, etc.
- If applicable, which third-party component is affected?
- Tools and methods to uncover and exploit the vulnerability
- Steps to reproduce the vulnerability
- If available, a proof of concept (e.g. exploitation code) that the vulnerability can be exploited in practice
- Privileges required to exploit the vulnerability
- Evidence if the vulnerability is already actively exploited
- Optional: Your contact information and whether it is permissible that EVIDENT will forward your contact information to a third-party vendor in case the vulnerability was found in a third-party component used inside one of our products or services.
Upon submitting a vulnerability report, you grant EVIDENT a non‑exclusive, worldwide, royalty‑free right to use, reproduce, and share the submitted information solely for the purposes of investigating, validating, remediating, and disclosing the reported vulnerability in a responsible manner.
EVIDENT will treat vulnerability reports and related information with appropriate care and will not use such information for purposes unrelated to product security, vulnerability handling, or compliance with applicable legal and regulatory requirements.
You agree that submitting any information does not create any rights for you (other than as expressly set out in this policy) or any contractual obligations for EVIDENT beyond those mandated by applicable law.
Coordinated Disclosure, Response Process and Commitment
Upon receipt of a vulnerability report, EVIDENT will:
- Strive to acknowledge receipt of the report as soon as reasonably practicable, if you supplied your contact information and did not choose to report anonymously. EVIDENT will provide you with a unique tracking number to refer to this topic.
- Offer you the option to continue communication with EVIDENT securely (e.g. by using email encryption) and request your collaboration if clarification is required
- Verify the reported vulnerability by our Product Security Incident Response Team (PSIRT)
- Work on a resolution and perform validation on the resolution
- Take appropriate action (e.g. by disclosing this information, providing a security update, etc.)
- In case the reported vulnerability is found in a third-party component in one of our products or services, EVIDENT may share the vulnerability details necessary for remediation with the relevant third-party vendor. Your contact information will be forwarded to the third‑party vendor only if you have explicitly consented to such disclosure. If no consent is given, EVIDENT will, where feasible, communicate the vulnerability without disclosing your identity or personal contact details.
EVIDENT follows a coordinated and risk‑based approach to public vulnerability disclosure.
Disclosure timing may be adjusted where reasonable and appropriate, including but not limited to:
- complexity of remediation or validation,
- dependencies on third‑party components or suppliers, or
- the need to prevent disproportionate risk to users, customers, or patient safety.
Earlier disclosure may be considered where a vulnerability is actively exploited, poses a high or imminent risk, or where regulatory or risk‑mitigation considerations require urgent communication.
In the case of zero‑day vulnerabilities, EVIDENT may provide staged or limited disclosures, including interim mitigations or workarounds, prior to the availability of a full fix, in order to reduce risk while remediation is underway.
In support of this approach, EVIDENT will:
- Work with you to discuss reasonable, risk-based public disclosure timing.
- Use existing customer notification processes to disclose the vulnerability in direct customer communication, if appropriate. This may include provision of preliminary workarounds until a public resolution is in place.
- Publish vulnerability advisories once a fix is available or otherwise in accordance with proportionate, risk-based communication considerations under the CRA or other applicable laws, where applicable
For EVIDENT, patient safety takes precedence over disclosure timing. Therefore, EVIDENT may decide to withhold certain disclosure details temporarily to prevent harm.
Reporting Obligations to the EU Authorities as Mandated by the CRA, Article 14
The assessment above also ascertains whether the report is related to
- an actively exploited vulnerability and / or
- a severe incident having impact on the security of our products.
in terms of the CRA.
If this is the case, where applicable, EVIDENT will notify the EU authorities as mandated by the CRA in article 14 via the Single Reporting Platform (SRP) operated by the ENISA. EVIDENT maintains internal processes designed to support compliance with applicable CRA reporting obligations.
Subject to applicable law, in addition to those reporting obligations under the CRA, EVIDENT may report vulnerabilities to national CERTs.
The CRA does not apply to products with digital elements to which the MDR or IVDR apply.
Commitment to Non-Retaliation ("Safe Harbor")
If you act in good faith and in accordance with this Coordinated Vulnerability Disclosure policy, EVIDENT will not initiate legal action against you for your vulnerability research and reporting activities. This commitment is given by EVIDENT only and does not bind, waive, or limit any rights or claims of third parties, including customers, users, regulators, or other vendors.
EVIDENT considers security research conducted under this policy to be authorized, provided that you:
- make a good‑faith effort to avoid privacy violations, service disruption, or adverse impact to users, patients, or customers;
- limit your activities to what is reasonably necessary to validate the existence of a vulnerability;
- comply with the “Responsible Actions and Responsible Research” section of this policy; and
- promptly report discovered vulnerabilities to EVIDENT and do not publicly disclose them before coordinated disclosure is agreed.
This Safe Harbor does not apply to activities that are unlawful, conducted recklessly, involve intentional harm, unauthorized access, access to customer or patient data, circumvention of legal prohibitions, data exfiltration beyond what is necessary to demonstrate the vulnerability, extortion, social engineering, testing in customer environments or production systems without authorization, or actions performed outside the scope of this policy.
EVIDENT reserves the right to pursue appropriate action in cases of malicious intent, bad faith, or non‑compliance with applicable laws and regulations.
Scope of Authorized Testing, Responsible Actions and Responsible Research
Authorized vulnerability research under this policy is limited to EVIDENT products and services that are intentionally made available for testing, including dedicated test, demo, or development environments, and publicly accessible interfaces explicitly intended for customer or user interaction.
Except for components, systems, and environments that EVIDENT intentionally makes available for testing under this policy, testing must be performed only on components, systems, and accounts owned or controlled by the researcher, and only using techniques that do not degrade system availability, compromise patient safety, or affect real users, customers, or patient data.
Testing activities outside this scope require explicit prior written authorization from EVIDENT.
Please follow the following guidelines to ensure responsible behavior:
- Be compliant with all laws and regulations during your research and testing activities.
- When submitting any information to EVIDENT or a 3rd party, make sure not to include any sensitive information like personally identifiable information (PII) or patient health information (PHI) in your communication. If you provide screenshots or other attachments, make sure to remove this information in a technically safe manner.
- Do not perform vulnerability testing or vulnerability research on products or services which are actively in use, especially not in patient care, patient diagnosis or patient monitoring. Instead, restrict your testing and research activities to demo or test environments, only. Refrain from taking any action which might disrupt the product or service (e.g. by performing a denial-of-service (DoS) attack).
- Do not utilize a vulnerability beyond what is absolutely necessary to establish its existence.
- Do not take advantage of the vulnerability you have discovered in any form. This includes – but is not limited to:
- accessing or downloading sensitive and / or private data
- altering or deleting data
- making changes or causing damage to a system
- Only use your own accounts and systems during testing; do not use social engineering to gain access to the accounts of other people.
- Do not use brute force attacks to gain access to systems.
Data Protection
Any personal data you provide (such as your contact details) will be processed by EVIDENT solely for the purpose of handling and coordinating the reported vulnerability and for compliance with applicable legal obligations. Such data will be retained only as long as necessary for these purposes and will be processed in accordance with applicable data protection law and EVIDENT’s privacy policy available at https://evidentscientific.com/en/legal/privacy .
Bug Bounties or Hall of Honors
EVIDENT currently does not administer a bug bounty program. The reporter acknowledges that there is no payment or other compensation for reporting a vulnerability to EVIDENT.