Security

Vulnerability Reporting

Innocens BV · Version 01 · security@innocens.be

1. Scope of the policy

In scope

• The Innocens website and any subdomain we operate.

• The Intellicens Data Platform and Intellicens Neo.

• Any other software or service published by Innocens BV.

Out of scope

• Systems operated by our customers, including hospital infrastructure and hospital deployments of our software. These should be reported to the institution concerned.

• Third party services that we merely use, and infrastructure owned or operated by third parties.

• Findings that require physical access to a device, or a compromised user account.

• Social engineering of our staff, customers or suppliers.

• Denial of service testing, load testing, or any activity that degrades availability.

• Reports generated purely by an automated scanner, with no demonstrated impact.

• Missing best practice headers or configuration with no demonstrated exploit path.

Where it is not clear whether this policy applies to a specific product, service or piece of infrastructure, the participant should ask us at security@innocens.be and obtain written confirmation before continuing.

2. How to report

Send your report to security@innocens.be.

Please include the following:

• What the issue is and where you found it, with the exact URL, component or version.

• Steps to reproduce it, ideally with a proof of concept.

• What an attacker could achieve.

• Whether you accessed, modified or downloaded any data, and if so what.

• How you would like to be credited, if at all.

Write in English or Dutch.

If your report contains a working exploit, or anything else you would rather not send in plain email, send us a short note first and we will agree an encrypted channel with you. You may also send the details in a password protected file and pass the password to us separately.

3. Our commitments

• We acknowledge your report as soon as possible after we receive it.

• We tell you whether we accept the finding, and keep you informed of the follow-up.

• Taking into account the state of the art, the cost of implementation and the severity of the risk, we aim to have a solution within 90 calendar days. If we need longer we will tell you why.

• We credit you publicly for an accepted finding if you want that.

We do not operate a paid bug bounty programme.

4. What we ask of participants

• Act without fraudulent intent and without intent to harm.

• Remain proportionate. Do not go beyond what is necessary to demonstrate the vulnerability. If the issue has been demonstrated on a small scale, stop there.

• Do not access, modify, delete or store patient data or any other personal data. If you encounter personal data, stop and tell us immediately.

• Do not degrade or interrupt our services, or those of our customers.

• Do not disclose the vulnerability publicly before we have had a reasonable opportunity to fix it. We will agree the timing of any public disclosure with you.

• Do not use the finding for any purpose other than the report.

If you engage a third party to assist with your research, you must ensure that the third party is aware of this policy and agrees to abide by it. You remain responsible to us for their conduct.

5. Safe harbour

If you follow this policy in good faith, we will not initiate or support civil or criminal legal action against you in relation to your research, and we will treat your activity as authorised for the purposes of applicable computer crime legislation.

This protection does not extend to conduct outside this policy, and we cannot waive the rights of third parties, including our customers.

6. Belgian legal framework and the CCB

Belgium has a statutory framework for vulnerability research and reporting, set out in Articles 22 and 23 of the Law of 26 April 2024. Under that framework the Centre for Cybersecurity Belgium acts as national coordinator and can receive vulnerability reports directly.

Reporting to the CCB at vulnerabilityreport@ccb.belgium.be alongside your report to us is fully compatible with this policy, and is a condition of the statutory protection available to you. Where a vulnerability may affect other organisations in Belgium, either party may inform the CCB.

If either party stops responding within a reasonable time, the CCB may be asked to act as intermediary.

7. Regulatory reporting

Where a vulnerability affects a medical device and meets the applicable reporting criteria, we notify the competent authorities and affected customers in line with our obligations as a manufacturer, including our post-market surveillance and vigilance procedures.

Where a vulnerability has resulted in a personal data breach, the Data Protection Officer applies the notification assessment under Article 33 GDPR in parallel.

8. Applicable law and duration

Belgian law governs any dispute arising from this policy.

This policy applies from the effective date on the first page until it is amended or withdrawn. Any change is published on our website and takes effect 30 days after publication.