Coordinated Vulnerability Disclosure Policy

CVD Policy – preview

Welcome to Freenome’s Coordinated Vulnerability Disclosure Page

Freenome has mechanisms in place to identify and address vulnerabilities in its products and respond to the requirements of its customers and patients as well as authorities. At Freenome, we are committed to protecting and securing information associated with Freenome connected medical devices and information in order to protect the security and safety of patients and to comply with federal, state, and local laws. This page describes Freenome’s process for receiving reports related to potential cyber security vulnerabilities in its products and the company’s standard practice for informing customers and other required stakeholders of verified vulnerabilities. If you have discovered a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner.

Reporting a Vulnerability

We welcome reports from security researchers, industry partners, academia, and other users. To report a security vulnerability in our products, please use the following guidelines.

How to Report

  • Please contact us by sending an email to productsecurity@freenome.com. We will work with you to determine a secure solution to share your findings with us.
  • Once the secure form of communication has been established, please provide as much information as possible about the vulnerability, such as the following:
    • Product name, URL, or affected version information
    • The type of vulnerability (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
    • A description of the vulnerability and how it can be reproduced
    • The potential impact of the vulnerability
    • Any steps, tools, code, or scripts to reproduce the vulnerability
    • Reporter’s contact information
    • Time and date of discovery

What to Expect

  • Acknowledgment: We will acknowledge receipt of your vulnerability report within 5 business days.
  • Communication: We will keep you informed of the progress towards a fix and full announcement, and we may contact you for additional information about the vulnerability.
  • Confidentiality: Please keep your findings confidential between us until a fix has been developed and deployed.
  • Safe Harbor: We aim to keep all parties safe. If you follow these guidelines when reporting an issue to us, we commit not to pursue legal action against you.
  • Freenome is dedicated to reading and providing responses to reports of potential software security vulnerabilities in a timely manner.
  • Publishing vulnerability advisories: Freenome intends to publish vulnerability advisories to enable users to identify vulnerable products and services and take action to remediate confirmed vulnerabilities.

Our Commitment

Upon receiving a vulnerability report, Freenome commits to the following:

  • Promptly acknowledging receipt of your report
  • Providing an estimated timeline for addressing the vulnerability
  • Notifying you when the vulnerability is fixed
  • As Freenome’s diagnostic products are provided as a service, no external distribution of the software is needed.

Recognition

While we do not have a formal bug bounty program, we recognize and appreciate the effort and contribution of security researchers.

Legal Notice

This policy is intended to encourage the responsible disclosure of vulnerabilities and not to give permission to act in any manner that is inconsistent with the law or to conduct penetration testing on Freenome systems without explicit permission. Thank you for helping to keep Freenome and our users safe.

You are leaving this website

By selecting this link, you are leaving the Freenome website and will be directed to another web page.