Company
setpointmedical.com
Program URL
https://setpointmedical.com/security/
Contact
productsecurity@setpointmedical.com
Description
etPoint Medical is committed to ensuring our medical devices and systems are safe from vulnerabilities that would impact the integrity of our products or the privacy of our patients and customers. SetPoint Medical employs Secure by Design and Secure by Default principles in all its development efforts and has made cybersecurity an integral part of its Quality Management System.
As the cybersecurity landscape is constantly evolving and cyberattacks are consistently becoming more sophisticated, S
Rewards
Program type
bounty
Status
active
Safe harbor
No response
Allows disclosure
No response
Domains
No response
Structured scope
No response
Out of scope
Some categories of security reports are out of scope for our bug bounty reward program. These sorts of attack vectors often have already been considered and evaluated. Reports related to the following areas are considered out-of-scope for the bug bounty reward system:
Already-reported issues
Attacks against products that are not commercially available (including clinical trial devices)
Attacks against websites used solely for product marketing (SetPoint Medical devices interact with services on the setpointmedical.cloud domain)
Attacks against SetPoint Medical engineering, testing, and development systems
Reports from automated scanning tools
Social engineering and phishing attacks against patients, employees, or healthcare providers (including creation of counterfeit applications to harvest credentials)
SetPoint Medical’s internal business systems (i.e., those that do not interact with SetPoint Medical devices or patient information)
Attacks that require physical disassembly of devices
Communication denial-of-service attacks including, but not limited to, signal jamming, blocking of HTTP requests, and Distributed Denial of Service (DDOS)
Compromises due to credential stuffing attacks, or attacks that are results of user credentials existing in breach corpuses
While we cannot promise a response or reward for an out-of-scope category, all reports will still be considered and evaluated.
Excluded methods
Requires account
No response
Minimum payout
100
Maximum payout
10000
Currency
USD
Payout - critical
10000
Payout - high
No response
Payout - medium
1000
Payout - low
100
Swag details
No response
Testing policy URL
No response
Response SLA days
No response
Disclosure timeline days
No response
Legal terms URL
No response
Hall of fame URL
No response
Reporting URL
No response
PGP key URL
No response
Preferred languages
No response
Standards
No response
Confirmation
Company
setpointmedical.com
Program URL
https://setpointmedical.com/security/
Contact
productsecurity@setpointmedical.com
Description
etPoint Medical is committed to ensuring our medical devices and systems are safe from vulnerabilities that would impact the integrity of our products or the privacy of our patients and customers. SetPoint Medical employs Secure by Design and Secure by Default principles in all its development efforts and has made cybersecurity an integral part of its Quality Management System.
As the cybersecurity landscape is constantly evolving and cyberattacks are consistently becoming more sophisticated, S
Rewards
Program type
bounty
Status
active
Safe harbor
No response
Allows disclosure
No response
Domains
No response
Structured scope
No response
Out of scope
Some categories of security reports are out of scope for our bug bounty reward program. These sorts of attack vectors often have already been considered and evaluated. Reports related to the following areas are considered out-of-scope for the bug bounty reward system:
Already-reported issues
Attacks against products that are not commercially available (including clinical trial devices)
Attacks against websites used solely for product marketing (SetPoint Medical devices interact with services on the setpointmedical.cloud domain)
Attacks against SetPoint Medical engineering, testing, and development systems
Reports from automated scanning tools
Social engineering and phishing attacks against patients, employees, or healthcare providers (including creation of counterfeit applications to harvest credentials)
SetPoint Medical’s internal business systems (i.e., those that do not interact with SetPoint Medical devices or patient information)
Attacks that require physical disassembly of devices
Communication denial-of-service attacks including, but not limited to, signal jamming, blocking of HTTP requests, and Distributed Denial of Service (DDOS)
Compromises due to credential stuffing attacks, or attacks that are results of user credentials existing in breach corpuses
While we cannot promise a response or reward for an out-of-scope category, all reports will still be considered and evaluated.
Excluded methods
Requires account
No response
Minimum payout
100
Maximum payout
10000
Currency
USD
Payout - critical
10000
Payout - high
No response
Payout - medium
1000
Payout - low
100
Swag details
No response
Testing policy URL
No response
Response SLA days
No response
Disclosure timeline days
No response
Legal terms URL
No response
Hall of fame URL
No response
Reporting URL
No response
PGP key URL
No response
Preferred languages
No response
Standards
No response
Confirmation