Security & Vulnerability Disclosure
medVC.eu sp. z o.o. welcomes reports from security researchers and customers about potential vulnerabilities in our products and services.
Scope
- medVC software and services (medvc.eu and related endpoints)
- medVC medical devices and appliances, including medVC FHD and 4K Medical Video Recorders
Out of scope: denial-of-service testing, social engineering, physical attacks, spam, and issues in third-party services we do not operate.
How to report
Email security@medvc.eu. Please include: the product and version (or URL), a description of the issue, steps to reproduce, and your contact details. Please do not include patient data in reports.
What to expect
- We will acknowledge your report within 5 business days.
- We will keep you informed about the progress of triage and remediation.
- We follow coordinated disclosure: we ask you to give us reasonable time to remediate (as a rule 90 days) before public disclosure, and we will coordinate the disclosure timeline with you.
- With your consent, we will credit you once the issue is resolved.
Safe harbor
We will not initiate legal action against researchers who act in good faith: who avoid privacy violations, data destruction and service disruption, do not access or modify data beyond what is necessary to demonstrate the issue, and report findings to us promptly and confidentially.