Do you think you have found a vulnerability in CARYLIA SafeVault (appliance, console, Edge agent) or in this website? Please write to us before making it public: the healthcare facilities that use the product must be protected first.
How to reach us
At security@caryliahealth.com, subject “Vulnerability”, in English or French: the affected version, what you observed, the steps to reproduce it, and the impact you expect. Send no patient data, even if the flaw exposed some: describe it, do not copy it.
Our commitments
- Acknowledge receipt within 3 business days.
- Tell you within 10 business days whether the vulnerability is confirmed, and its severity.
- Fix within the following times — critical: 30 days; high: 60 days; medium: 90 days; low: the next release. Facilities receive a signed update, and a security advisory for any high or critical vulnerability.
- Agree with you on the publication date — by default 90 days after the report, earlier once a fix has shipped — and credit you if you wish.
- Report an actively exploited vulnerability to the competent authorities, as required by the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
What we ask of you
- Test on your own installation or a demonstration environment, never on a facility’s appliance without its written consent.
- Do not degrade the service, do not access data that is not yours, do not keep it.
- Allow time for a fix before any publication.
Research carried out in good faith within this framework will not be pursued by us.
The French version prevails. security.txt file (RFC 9116). Last updated: 6 October 2026.
