Security
Vulnerability disclosure policy
Last updated: October 2026
The security of our platform and of the patient data our customers entrust to us is a priority. If you believe you have found a security vulnerability in an aiomics system, we want to hear from you. This page explains how to report it and what you can expect from us.
How to report a vulnerability
Email your report to security@aiomics.io. Please include:
- The affected URL, domain, application or other asset.
- A description of the vulnerability and the steps needed to reproduce it.
- The impact you believe it has and how an attacker could exploit it.
- How we can reach you, and the name or handle you would like to be credited with.
Include proof-of-concept code or screenshots only to the extent needed to demonstrate the issue, and never send us patient or other personal data. Reports in English or German are welcome.
What we commit to
- We acknowledge your report within 3 working days.
- We send you an initial assessment within 7 days.
- We keep you informed of our progress until the issue is fixed.
- We coordinate any public disclosure with you.
- If you wish, we credit you in our Hall of Fame once the issue is resolved.
Rules for testing
When investigating a potential vulnerability, please:
- Test only against accounts that you own or are explicitly permitted to use.
- Never access, modify, download or keep patient data or other users' data beyond the minimum needed to demonstrate the issue. If you encounter such data, stop testing, do not share it, and report it to us immediately.
- Do not perform denial-of-service or other volumetric testing, social engineering (including phishing), physical attacks or spam.
- Give us reasonable time to fix the issue before you disclose it to anyone else.
Out of scope
The following are out of scope, for example:
- Missing or weak DMARC, SPF or DKIM records on domains that do not send email.
- Clickjacking on pages without sensitive actions.
- Missing security headers without a demonstrated impact.
- Self-XSS, meaning issues that users can only trigger against themselves.
- Missing rate limiting on endpoints that do not handle authentication.
- Vulnerabilities in third-party services that we do not control. Please report these directly to the vendor concerned.
Rewards
We do not offer monetary rewards (bug bounty) at this time. If you wish, we are glad to acknowledge your contribution publicly in our Hall of Fame.