Our commitment
MVision AI develops AI-powered radiotherapy planning software used in clinical care. The security of our products directly affects patient safety, and we take every report seriously. We value the work of security researchers and welcome reports of potential vulnerabilities in our products and infrastructure, made in good faith.
This policy describes what systems are in scope, how to report a vulnerability to us, what you can expect from us, and the protections we extend to good-faith researchers.
Scope
In scope:
- The MVision AI public website (mvision.ai) and its subdomains
- MVision Workspace+ and its modules
- MVision AI cloud infrastructure and APIs operated by MVision AI
- Client applications published by MVision AI
Out of scope:
- Production systems at hospitals and clinics using our software. Never test against live clinical deployments. These systems are involved in active patient care, and testing against them may endanger patients and will not be covered by our safe harbor commitment.
- Systems and services operated by third parties (e.g. hosting providers, payment processors), unless the vulnerability arises from our configuration of them
- Social engineering of MVision AI staff, customers, or partners
- Physical attacks against MVision AI offices or data centres
- Denial-of-service testing of any kind
- Spam, phishing simulations, or attacks requiring stolen credentials
If you are uncertain whether a system is in scope, contact us at security@mvision.ai before testing.
How to report
Email security@mvision.ai. If you wish to encrypt your report, our PGP key is available at mvision.ai/.well-known/security.txt
A useful report includes:
- A description of the vulnerability and its potential impact
- The product, version, URL, or component affected
- Step-by-step instructions to reproduce the issue (proof-of-concept code, screenshots, or logs are welcome)
- Any relevant configuration details of your test environment
- Your name/handle and contact details, if you wish to be credited (anonymous reports are accepted)
Please report in English.
What you can expect from us
- Acknowledgement of your report within 5 business days
- An initial assessment of severity and validity within 10 business days
- Regular updates on remediation progress, at least every 30 days for confirmed vulnerabilities
- Notification when the vulnerability has been remediated
- Public credit for your finding, if you wish, once a fix is available
Because our products are regulated medical devices (FDA-cleared and CE-marked under EU MDR), some fixes require verification, validation, and in some cases regulatory assessment before release. Remediation timelines may therefore be longer than for conventional software. We will be transparent with you about expected timelines and the reasons for them.
Coordinated disclosure
We ask that you:
- Give us a reasonable opportunity to remediate before any public disclosure. Our default coordinated disclosure window is 90 days from acknowledgement; for vulnerabilities requiring regulatory or clinical-safety review, we may request an extension, and we will explain why.
- Do not access, modify, or delete data belonging to others. If you encounter patient data or other personal data during testing, stop immediately, do not copy or retain it, and report it to us.
- Limit testing to the minimum necessary to demonstrate the vulnerability.
- Do not degrade the availability or integrity of our services.
We will coordinate public disclosure with you, and where appropriate we will notify affected customers and relevant authorities (including under EU MDR vigilance and FDA postmarket cybersecurity expectations) as part of our remediation process.
Safe harbor
If you make a good-faith effort to comply with this policy, MVision AI will:
- Not initiate or support legal action against you for your research
- Not report your research to law enforcement as a malicious act
- Consider your research authorised under applicable anti-hacking and anti-circumvention laws, to the extent we are able to grant such authorisation
- Work with you to understand and resolve the issue quickly
This safe harbor does not apply to testing against out-of-scope systems (in particular live clinical deployments), to actions that intentionally harm MVision AI, our customers, or patients, or to violations of applicable law that are unrelated to this policy. We cannot authorise testing of third-party systems; contact the relevant third party for their policy.
Recognition
We do not currently operate a paid bug bounty programme. With your consent, we will credit valid, first-reported vulnerabilities on our security acknowledgements page.
Questions
For questions about this policy, contact security@mvision.ai.
