Reporting a security vulnerability

TheraPanacea develops software used in the planning and delivery of radiotherapy treatment. We take
reports of security vulnerabilities in our products seriously, and we would rather hear about one
from you than from an attacker.

How to reach us

Email security@therapanacea.com.

If your report contains sensitive detail, encrypt it with our PGP key:

Anyone may report. You do not need an account, a contract or any prior relationship with us, and
you may report anonymously.

What helps

The product and version, what you found, how to reproduce it, and the configuration you observed it
in. Any public reference, such as a CVE identifier. None of this is required — send what you have and
we will ask for the rest.

What we will do

  1. Acknowledge your report | within 3 business days

  2. Triage it and tell you what we found | within 10 business days

  3. Keep you updated while it is open | at least every 30 days

  4. Publish, coordinated with you | 90 days after acknowledgement by default

  5. Credit you in the advisory | unless you ask us not to

We fix confirmed vulnerabilities on the timelines of our vulnerability management policy, and out of
cycle where the severity or an active-exploitation signal calls for it.

We do not run a paid bug bounty programme.

Research we consider to be in good faith

We will not pursue legal action for security research conducted in good faith under this policy, and
we treat such research as authorised. Good faith means you:

  • report what you find rather than exploit it;

  • never access, extract, alter or keep patient data — if you encounter any, stop and tell us;

  • use only your own data or test data, and only systems you are entitled to use;

  • do not degrade or disrupt a production service — no denial-of-service, spam or social engineering;

  • go no further into a vulnerability than needed to demonstrate it;

  • give us a reasonable time to fix it before going public.

One request specific to what we build. Our products may be in use in the treatment of a
patient. Never test against a clinical production environment without the written agreement of
whoever operates it. If you believe you have found something that affects patient safety, say so in
your first message and we will treat it as such immediately.

Customers

If a vulnerability affects a released product, we notify affected customers directly through the
channel we use for security updates, with the affected versions, the fix, and any interim mitigation.