Skip to content

[Program]: setpointmedical.com #139

Description

@batamaji

Company

setpointmedical.com

Program URL

https://setpointmedical.com/security/

Contact

productsecurity@setpointmedical.com

Description

etPoint Medical is committed to ensuring our medical devices and systems are safe from vulnerabilities that would impact the integrity of our products or the privacy of our patients and customers. SetPoint Medical employs Secure by Design and Secure by Default principles in all its development efforts and has made cybersecurity an integral part of its Quality Management System.

As the cybersecurity landscape is constantly evolving and cyberattacks are consistently becoming more sophisticated, S

Rewards

  • *bounty
  • *recognition
  • *swag

Program type

bounty

Status

active

Safe harbor

No response

Allows disclosure

No response

Domains

No response

Structured scope

No response

Out of scope

Some categories of security reports are out of scope for our bug bounty reward program. These sorts of attack vectors often have already been considered and evaluated. Reports related to the following areas are considered out-of-scope for the bug bounty reward system:

Already-reported issues
Attacks against products that are not commercially available (including clinical trial devices)
Attacks against websites used solely for product marketing (SetPoint Medical devices interact with services on the setpointmedical.cloud domain)
Attacks against SetPoint Medical engineering, testing, and development systems
Reports from automated scanning tools
Social engineering and phishing attacks against patients, employees, or healthcare providers (including creation of counterfeit applications to harvest credentials)
SetPoint Medical’s internal business systems (i.e., those that do not interact with SetPoint Medical devices or patient information)
Attacks that require physical disassembly of devices
Communication denial-of-service attacks including, but not limited to, signal jamming, blocking of HTTP requests, and Distributed Denial of Service (DDOS)
Compromises due to credential stuffing attacks, or attacks that are results of user credentials existing in breach corpuses
While we cannot promise a response or reward for an out-of-scope category, all reports will still be considered and evaluated.

Excluded methods

  • dos
  • social_engineering
  • phishing
  • physical_access
  • automated_scanning

Requires account

No response

Minimum payout

100

Maximum payout

10000

Currency

USD

Payout - critical

10000

Payout - high

No response

Payout - medium

1000

Payout - low

100

Swag details

No response

Testing policy URL

No response

Response SLA days

No response

Disclosure timeline days

No response

Legal terms URL

No response

Hall of fame URL

No response

Reporting URL

No response

PGP key URL

No response

Preferred languages

No response

Standards

No response

Confirmation

  • I confirm the information is accurate and I have included only publicly documented program details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    submission-processedBot has parsed this submission and opened a PR

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions