Our commitment
Aiforia takes the security of its products and services seriously. We welcome reports from security researchers and others, and we are committed to working with you to verify, address, and responsibly disclose vulnerabilities.
What this covers
This policy applies to all Aiforia products with digital elements and Aiforia-operated internet-facing systems and domains.
The following are not covered, and we ask you not to test them: third-party services we do not operate; customer-operated deployments and any customer data within them; and anything requiring physical access to a customer site. If you believe you have found an issue in a product that affects customer deployments, report the underlying product issue to us and we will address it across affected customers.
How to report
Email security@aiforia.com. For sensitive reports, please encrypt using our published key (linked from this page and from security.txt).
Please include:
-
what the vulnerability is and where you found it (product/service, URL, version, or component);
-
how to reproduce it, with any proof-of-concept material;
-
the impact as you understand it; and
-
how you would like to be credited, or whether you prefer to remain anonymous.
English or Finnish is preferred.
What we ask of you
Because Aiforia systems can process clinical and personal data, safe testing matters. Please:
-
do not access, modify, copy, store, or remove data that is not your own — use only test accounts and data you are authorized to use;
-
stop immediately if you encounter personal data, patient data, or protected health information — do not view, download, or keep it; record only what is needed to describe the finding and tell us so we can act;
-
do not disrupt services — no denial-of-service, no destructive testing, no high-volume automated scanning that degrades service;
-
do not use social engineering, phishing, or physical intrusion against Aiforia staff, customers, or facilities;
-
keep the vulnerability confidential until we have agreed coordinated disclosure with you; and
-
comply with applicable law.
What you can expect from us
Working days are Aiforia business days (EET/EEST).
Stage |
Target |
|
We acknowledge your report |
within 3 working days |
|
We complete initial triage and share our initial view |
within 10 working days |
|
We keep you updated until resolution |
at least every 20 working days |
|
We remediate |
prioritized by severity; critical issues expedited |
|
We coordinate public disclosure with you |
by default within 90 days of triage, or when a fix is available — whichever is sooner |
Coordinated disclosure
We practice coordinated disclosure: please keep details confidential until a fix or mitigation is available and affected users have had a reasonable opportunity to apply it. We will agree timing with you and will not unreasonably delay disclosure. Once a fix is available, Aiforia publishes a security advisory for affected products describing the issue, affected versions, impact and severity, and the action users should take, and requests a CVE identifier where appropriate.
Recognition
We do not currently run a paid bug-bounty programme. With your consent, we are glad to credit the first reporter of a valid, previously unknown vulnerability on our acknowledgments page.
Safe harbor
If you make a good-faith effort to comply with this policy, we consider your research authorized: we will not initiate or recommend legal action against you for it, and if a third party brings action against you for activity that complied with this policy, we will make our authorization known. This authorization does not extend to actions that break the law, that access or disclose personal or patient data, or that harm Aiforia, its customers, or third parties.