Security

Report a vulnerability

Coordinated vulnerability disclosure policy for CARYLIA SafeVault and this website.

Do you think you have found a vulnerability in CARYLIA SafeVault (appliance, console, Edge agent) or in this website? Please write to us before making it public: the healthcare facilities that use the product must be protected first.

How to reach us

At security@caryliahealth.com, subject “Vulnerability”, in English or French: the affected version, what you observed, the steps to reproduce it, and the impact you expect. Send no patient data, even if the flaw exposed some: describe it, do not copy it.

Our commitments

  • Acknowledge receipt within 3 business days.
  • Tell you within 10 business days whether the vulnerability is confirmed, and its severity.
  • Fix within the following times — critical: 30 days; high: 60 days; medium: 90 days; low: the next release. Facilities receive a signed update, and a security advisory for any high or critical vulnerability.
  • Agree with you on the publication date — by default 90 days after the report, earlier once a fix has shipped — and credit you if you wish.
  • Report an actively exploited vulnerability to the competent authorities, as required by the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

What we ask of you

  • Test on your own installation or a demonstration environment, never on a facility’s appliance without its written consent.
  • Do not degrade the service, do not access data that is not yours, do not keep it.
  • Allow time for a fix before any publication.

Research carried out in good faith within this framework will not be pursued by us.

The French version prevails. security.txt file (RFC 9116). Last updated: 6 October 2026.