Product Security and Coordinated Vulnerability Disclosure Policy (CVD)
1. Purpose and intent
ONALABS Inno-Hub SL designs and maintains connected products and is committed to protecting the security of those products and the safety and privacy of the people who use them. We recognise that no product is free of vulnerabilities, and that security researchers play a valuable role in helping us find and fix them. This policy sets out our commitment to product security and how we work with the security community through coordinated vulnerability disclosure (CVD).
2. Scope
This policy applies to all ONALABS products with digital elements and their components — the device (firmware and hardware), the companion mobile application, and the associated cloud services — across our portfolio of medical and non-medical products. It does not cover ONALABS’ corporate IT systems, which are governed separately.
3. Our security commitment
ONALABS commits to:
- design and develop our products with security in mind, proportionate to their risks;
- maintain a process to receive, assess and remediate reported vulnerabilities throughout each product’s support period;
- provide security updates and inform affected users where appropriate;
- coordinate the public disclosure of vulnerabilities responsibly; and
- meet our legal obligations for product cybersecurity under the regulations applicable to each product (see §7).
4. Reporting a vulnerability
If you believe you have found a security vulnerability in an ONALABS product, please contact us at:
- Email: technical.support@onalabs.com
- Online: https://onalabs.com/en/cvd-policy/
- security.txt: https://onalabs.com/.well-known/security.txt
Please include enough information to reproduce and assess the issue (affected product/version, a description, and any proof-of-concept). Do not include more personal data than necessary.
5. Our commitments to reporters
- Safe harbour. We will not pursue or support legal action against researchers who act in good faith under this policy.
- Acknowledgement of your report within 5 business days.
- Initial assessment shared within 10 business days.
- Remediation timeline communicated within 30 calendar days.
- Coordinated disclosure. We ask for up to 90 calendar days from your initial report before public disclosure, extendable by mutual agreement, so users can be protected before details are public.
- Recognition. With your consent, we are happy to credit your contribution.
6. What we ask of reporters
Act in good faith; avoid privacy violations, data destruction and service disruption; access only the minimum data needed to demonstrate the issue; do not exploit the vulnerability beyond proof-of-concept; and give us reasonable time to remediate before disclosing publicly.
7. Legal and regulatory context
ONALABS handles vulnerabilities in line with the cybersecurity obligations applicable to each product:
- Non-medical products — the EU Cyber Resilience Act (Regulation (EU) 2024/2847), including its coordinated-disclosure and reporting requirements.
- Medical devices — the EU Medical Device Regulation (Regulation (EU) 2017/745) and applicable cybersecurity guidance (MDCG 2019-16), including post-market surveillance and vigilance.