Vulnerability Disclosure Policy (VDP)
1. Introduction
At niostem, the security of our users and their health data is a top priority. We appreciate the work of security researchers and welcome reports regarding potential vulnerabilities in our wearable device, mobile applications, or cloud infrastructure.
2. Reporting a Vulnerability
If you believe you have found a security vulnerability, please submit a report to our security team:
-
Email: security@niostem.com
-
PGP Key: PGP Key: [https://manebiotech.fra1.cdn.digitaloceanspaces.com/PGP/pgp-key.asc ]
PGP Fingerprint: 047BA60050CE147581E359A4952D7CE602EEB436 -
Required Information:
-
Product model and software/firmware version.
-
A description of the issue and its potential impact.
-
Steps to reproduce the vulnerability (PoC).
-
3. Our Commitment
Upon receipt of a valid report, we commit to:
-
Acknowledgment: Confirming receipt within 3 business days.
-
Investigation: Verifying the vulnerability and determining the risk level.
-
Resolution: Providing timely updates and working toward a fix.
-
Non-Retaliation: We will not take legal action against researchers who act in good faith and follow this policy.
4. Guidelines for Researchers
-
Do not attempt to access, modify, or delete user data.
-
Do not perform Denial of Service (DoS) attacks.
-
Give us a reasonable amount of time to fix the issue before any public disclosure.
V01 17.10.2026