Coordinated Vulnerability Disclosure Policy

smartpatient GmbH — MyTherapy — Last updated: 21 Jul 2026 · Version 1.0

Our Commitment

At smartpatient GmbH, the security of MyTherapy and the privacy of our users are our top priorities. We recognise that security researchers and members of the public play an important role in keeping our products safe. We welcome responsible reports of potential security vulnerabilities in any of our products or services.

This policy explains how to report a vulnerability to us, what you can expect from us in return, and how we will handle your report.

This policy is published in accordance with Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) and follows the principles of ISO/IEC 29147 (Vulnerability Disclosure) and ISO/IEC 30111 (Vulnerability Handling Processes).

Scope

This policy applies to the following products and services operated by smartpatient GmbH:

If you discover a vulnerability in a third-party product or service that we use, please report it directly to that vendor. We are happy to assist in routing your report if needed.

How to Report a Vulnerability

Please send your vulnerability report to:

Email: security@smartpatient.eu

To help us process your report quickly, please include as much of the following information as possible:

You may encrypt your report using our PGP public key. Key fingerprint: DC7F159A2DE2CCB8F57ADAD1CA91A7FD32E88282.

What You Can Expect from Us

We are committed to working with you in good faith. Once we receive your report, we will:

Step Timeline
Acknowledge your report Within 3 business days
Confirm whether the vulnerability is valid and in scope Within 15 business days
Provide an update on remediation progress Every 30 days until resolved
Notify you when the vulnerability has been fixed Upon resolution

We aim to resolve critical and high-severity vulnerabilities within 30 days of confirmation. For complex issues, we will agree a timeline with you and keep you informed throughout.

Our Commitments to You

If you report a vulnerability in good faith and follow this policy, we commit to:

What We Ask of You

To ensure a safe and constructive process, we ask that you:

Coordinated Disclosure

We follow a coordinated disclosure approach. This means:

  1. You report the vulnerability to us privately.
  2. We investigate, confirm, and work on a fix.
  3. Once a fix is available, we agree a disclosure date with you.
  4. We publish a security advisory and you may publish your findings simultaneously.

We ask that you allow us a minimum of 90 days from the date of confirmation before any public disclosure. If we need more time due to complexity, we will communicate this clearly and agree an extension with you.

If a vulnerability is being actively exploited in the wild, we may accelerate this timeline.

Severity Classification

We assess vulnerabilities using the Common Vulnerability Scoring System (CVSS):

Severity CVSS Score Target Remediation Time
Critical 9.0 – 10.0 7 days
High 7.0 – 8.9 30 days
Medium 4.0 – 6.9 60 days
Low 0.1 – 3.9 90 days

Out of Scope

The following are outside the scope of this policy and should not be tested:

Regulatory Reporting

In accordance with the EU Cyber Resilience Act, smartpatient GmbH may be required to notify the relevant national CSIRT (Computer Security Incident Response Team) and ENISA of certain actively exploited vulnerabilities. Where this applies, we will handle such notifications in line with our legal obligations.

Contact

smartpatient GmbH, Neumarkter Str. 87, 81673 München, Germany

This policy is reviewed annually and updated as needed. For questions about this policy, please contact security@smartpatient.eu.