Adagio Medical · Vulnerability Disclosure

Adagiomedical Vulnerability Disclosure

Vulnerability disclosure

Adagio Medical publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyMedical DevicesHealthCardiologyMedical TechnologyCryoablationElectrophysiology
Program: security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
product_security@adagiomedical.com

Source

Vulnerability Disclosure

adagiomedical-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-06'
method: searched
probe: true
source: https://adagiomedical.com/us/product-security
summary: >-
  Adagio Medical publishes a first-party coordinated vulnerability disclosure (CVD) policy for its
  medical devices and services on its own corporate site. It is a device-manufacturer PSIRT-style
  policy — not a bug bounty and not an RFC 9116 security.txt — and it is the only security program
  the company publishes. No /.well-known/security.txt is served on any Adagio Medical host
  (see well-known/adagiomedical-well-known.yml).
policy:
- https://adagiomedical.com/us/product-security
- https://adagiomedical.com/eu/product-security
contact:
- product_security@adagiomedical.com
program:
  type: coordinated-disclosure
  bug_bounty: false
  bounty_platform: null
  preferred_language: English
  acknowledgement_sla: five business days to confirm receipt and name a contact person
  public_credit: offered, subject to reporter agreement
  regulator_alternative: >-
    The policy explicitly tells a reporter who prefers to disclose to a regulator rather than to
    Adagio Medical to contact the appropriate regulatory agency directly.
  scope_notes: >-
    Reporters are asked to comply with all laws, and to avoid brute-force testing, tests on active
    devices, tests on software in production settings, exploitation of any vulnerability, and any
    action that changes a product or system after testing. Reporters are asked NOT to include
    protected health information or other personally identifiable information in a submission.
  requested_details:
  - reporter contact information (name, organization, email, phone)
  - when, where and how the issue was discovered
  - affected products/devices/systems including product numbers
  - whether PHI or other PII was accessible
  - testing environment and tools used
  - whether any other party (regulator, vendor, coordinator) has been notified
security_txt: false
evidence:
- source: https://adagiomedical.com/us/product-security
  kind: coordinated-disclosure-page
  http_status: 200
  fetched: '2026-09-06'
  keywords: [coordinated disclosure, security vulnerability, product_security@adagiomedical.com, security research community]
- source: https://adagiomedical.com/.well-known/security.txt
  kind: security.txt
  http_status: 404
  fetched: '2026-09-06'
  note: not served; the host returns its Next.js 404 HTML page

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/adagiomedical-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.