smartpatient GmbH — MyTherapy — Last updated: 21 Jul 2026 · Version 1.0
Our Commitment
At smartpatient GmbH, the security of MyTherapy and the privacy of our users are our top priorities. We recognise that security researchers and members of the public play an important role in keeping our products safe. We welcome responsible reports of potential security vulnerabilities in any of our products or services.
This policy explains how to report a vulnerability to us, what you can expect from us in return, and how we will handle your report.
This policy is published in accordance with Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) and follows the principles of ISO/IEC 29147 (Vulnerability Disclosure) and ISO/IEC 30111 (Vulnerability Handling Processes).
Scope
This policy applies to the following products and services operated by smartpatient GmbH:
If you discover a vulnerability in a third-party product or service that we use, please report it directly to that vendor. We are happy to assist in routing your report if needed.
How to Report a Vulnerability
Please send your vulnerability report to:
Email: security@smartpatient.eu
To help us process your report quickly, please include as much of the following information as possible:
You may encrypt your report using our PGP public key. Key fingerprint: DC7F159A2DE2CCB8F57ADAD1CA91A7FD32E88282.
What You Can Expect from Us
We are committed to working with you in good faith. Once we receive your report, we will:
| Step | Timeline |
|---|---|
| Acknowledge your report | Within 3 business days |
| Confirm whether the vulnerability is valid and in scope | Within 15 business days |
| Provide an update on remediation progress | Every 30 days until resolved |
| Notify you when the vulnerability has been fixed | Upon resolution |
We aim to resolve critical and high-severity vulnerabilities within 30 days of confirmation. For complex issues, we will agree a timeline with you and keep you informed throughout.
Our Commitments to You
If you report a vulnerability in good faith and follow this policy, we commit to:
What We Ask of You
To ensure a safe and constructive process, we ask that you:
Coordinated Disclosure
We follow a coordinated disclosure approach. This means:
We ask that you allow us a minimum of 90 days from the date of confirmation before any public disclosure. If we need more time due to complexity, we will communicate this clearly and agree an extension with you.
If a vulnerability is being actively exploited in the wild, we may accelerate this timeline.
Severity Classification
We assess vulnerabilities using the Common Vulnerability Scoring System (CVSS):
| Severity | CVSS Score | Target Remediation Time |
|---|---|---|
| Critical | 9.0 – 10.0 | 7 days |
| High | 7.0 – 8.9 | 30 days |
| Medium | 4.0 – 6.9 | 60 days |
| Low | 0.1 – 3.9 | 90 days |
Out of Scope
The following are outside the scope of this policy and should not be tested:
Regulatory Reporting
In accordance with the EU Cyber Resilience Act, smartpatient GmbH may be required to notify the relevant national CSIRT (Computer Security Incident Response Team) and ENISA of certain actively exploited vulnerabilities. Where this applies, we will handle such notifications in line with our legal obligations.
Contact
smartpatient GmbH, Neumarkter Str. 87, 81673 München, Germany
This policy is reviewed annually and updated as needed. For questions about this policy, please contact security@smartpatient.eu.