Our customers trust us to act as a custodian of sensitive patient and customer information. We are honoured to have that trust placed in us and consequently take our responsibility to protect that information extremely seriously. We use our Privacy and Security Programs to ensure the confidentiality, availability and integrity of information. Our Security Team runs our Security Program and maintains this page for stakeholders interested in the Security Program.
Our solution is certified in accordance with the ISO/IEC 27001:2013 standard for Information Security Management Systems (ISMS), demonstrating our commitment to protecting private health information, quality, and governance.
Please contact the security team by emailing [email protected] if you have any questions or concerns that are not addressed in our Frequently Asked Questions (FAQ).
Cardihab welcomes the responsible disclosure of vulnerability reports from anyone who finds a security issue with our products. We look forward to working with the security community to resolve security vulnerabilities so we can keep patient information safe and continuously improve our security practices.
Cardihab will make a best effort to meet the following response targets for researchers contributing to our program:
Cardihab appreciates all the help it can get to keep the patient data safe and improve our security. However, please do not:
When reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:
Any activities conducted in a manner consistent with this policy will be considered authorised conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keeping patient data safe!