Aerin Medical · Vulnerability Disclosure

Aerin Medical Vulnerability Disclosure

Vulnerability disclosure

Aerin Medical runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyMedical DevicesHealthcareENTOtolaryngologyRhinologyRadiofrequency AblationNasal Airway ObstructionChronic RhinitisPhysician LocatorPrivate Company
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@aerinmedical.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-31'
method: searched
probe: true
source: https://aerinmedical.com/cybersecurity/
program: Coordinated Vulnerability Disclosure Policy
policy:
- https://aerinmedical.com/cybersecurity/
contact:
- security@aerinmedical.com
listed_from: https://aerinmedical.com/compliance/
policy_last_updated: '2024-08-09'
scope: >-
  The Aerin Console developed by Aerin Medical, including the device-related software,
  hardware and associated systems. Explicitly not a channel for product complaints or
  quality issues.
submission:
  channel: email
  address: security@aerinmedical.com
  subject_line: Vulnerability Disclosure Program
  required_fields:
  - contact information
  - product name and version
  - detailed description of the vulnerability
  - date and time discovered
  - how the vulnerability was identified
  - steps to reproduce
  - supporting screenshots, videos or code snippets
  requested_fields:
  - evidence of active exploitation
  - potential impact and risk
  - potential remediation
  - plans or intentions for public disclosure
  guidance:
  - Use encryption to protect sensitive information or attachments.
  - Do not include personal information in the initial report.
response_commitments:
  acknowledgement_sla: 5 business days
  commitments:
  - Investigate the reported vulnerability.
  - Communicate findings to the product team and conduct a risk analysis.
  - Provide a summary of findings and be transparent about remediation and timeline.
  - Maintain an open dialogue with status updates.
  - Disclose to customers and/or publish a security advisory as appropriate.
safe_harbor:
  offered: true
  terms: >-
    Aerin Medical will not pursue legal action or initiate law enforcement investigation
    against good-faith researchers who comply with the program rules, will not disclose the
    researcher's identity without consent unless required by law, and will not hold the
    researcher liable for damages arising from testing or reporting within scope.
bug_bounty:
  offered: false
  note: No monetary reward or bounty platform (HackerOne / Bugcrowd / Intigriti) is named.
pgp_key: null
security_advisories:
  published: false
  note: The policy page states Aerin Medical has no security advisories at this time.
gaps:
- No /.well-known/security.txt (RFC 9116) on any Aerin host, so the policy is undiscoverable
  by automated tooling despite existing.
- No PGP/OpenPGP key published for encrypted submissions, although encryption is requested.
- Scope covers the Aerin Console device only; the web properties (aerinmedical.com,
  vivaer.com, rhinaer.com) and the anonymously readable site API are not named in scope.
evidence:
- source: https://aerinmedical.com/cybersecurity/
  kind: disclosure-policy-page
  http_status: 200
  fetched: '2026-07-31'
- source: https://aerinmedical.com/compliance/
  kind: compliance-index-listing
  http_status: 200
  fetched: '2026-07-31'
- source: /.well-known/security.txt
  kind: security.txt
  http_status: 404
  fetched: '2026-07-31'