generated: '2026-09-06' method: searched probe: true source: https://adagiomedical.com/us/product-security summary: >- Adagio Medical publishes a first-party coordinated vulnerability disclosure (CVD) policy for its medical devices and services on its own corporate site. It is a device-manufacturer PSIRT-style policy — not a bug bounty and not an RFC 9116 security.txt — and it is the only security program the company publishes. No /.well-known/security.txt is served on any Adagio Medical host (see well-known/adagiomedical-well-known.yml). policy: - https://adagiomedical.com/us/product-security - https://adagiomedical.com/eu/product-security contact: - product_security@adagiomedical.com program: type: coordinated-disclosure bug_bounty: false bounty_platform: null preferred_language: English acknowledgement_sla: five business days to confirm receipt and name a contact person public_credit: offered, subject to reporter agreement regulator_alternative: >- The policy explicitly tells a reporter who prefers to disclose to a regulator rather than to Adagio Medical to contact the appropriate regulatory agency directly. scope_notes: >- Reporters are asked to comply with all laws, and to avoid brute-force testing, tests on active devices, tests on software in production settings, exploitation of any vulnerability, and any action that changes a product or system after testing. Reporters are asked NOT to include protected health information or other personally identifiable information in a submission. requested_details: - reporter contact information (name, organization, email, phone) - when, where and how the issue was discovered - affected products/devices/systems including product numbers - whether PHI or other PII was accessible - testing environment and tools used - whether any other party (regulator, vendor, coordinator) has been notified security_txt: false evidence: - source: https://adagiomedical.com/us/product-security kind: coordinated-disclosure-page http_status: 200 fetched: '2026-09-06' keywords: [coordinated disclosure, security vulnerability, product_security@adagiomedical.com, security research community] - source: https://adagiomedical.com/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-09-06' note: not served; the host returns its Next.js 404 HTML page