generated: '2026-07-31' method: searched probe: true source: https://aerinmedical.com/cybersecurity/ program: Coordinated Vulnerability Disclosure Policy policy: - https://aerinmedical.com/cybersecurity/ contact: - security@aerinmedical.com listed_from: https://aerinmedical.com/compliance/ policy_last_updated: '2024-08-09' scope: >- The Aerin Console developed by Aerin Medical, including the device-related software, hardware and associated systems. Explicitly not a channel for product complaints or quality issues. submission: channel: email address: security@aerinmedical.com subject_line: Vulnerability Disclosure Program required_fields: - contact information - product name and version - detailed description of the vulnerability - date and time discovered - how the vulnerability was identified - steps to reproduce - supporting screenshots, videos or code snippets requested_fields: - evidence of active exploitation - potential impact and risk - potential remediation - plans or intentions for public disclosure guidance: - Use encryption to protect sensitive information or attachments. - Do not include personal information in the initial report. response_commitments: acknowledgement_sla: 5 business days commitments: - Investigate the reported vulnerability. - Communicate findings to the product team and conduct a risk analysis. - Provide a summary of findings and be transparent about remediation and timeline. - Maintain an open dialogue with status updates. - Disclose to customers and/or publish a security advisory as appropriate. safe_harbor: offered: true terms: >- Aerin Medical will not pursue legal action or initiate law enforcement investigation against good-faith researchers who comply with the program rules, will not disclose the researcher's identity without consent unless required by law, and will not hold the researcher liable for damages arising from testing or reporting within scope. bug_bounty: offered: false note: No monetary reward or bounty platform (HackerOne / Bugcrowd / Intigriti) is named. pgp_key: null security_advisories: published: false note: The policy page states Aerin Medical has no security advisories at this time. gaps: - No /.well-known/security.txt (RFC 9116) on any Aerin host, so the policy is undiscoverable by automated tooling despite existing. - No PGP/OpenPGP key published for encrypted submissions, although encryption is requested. - Scope covers the Aerin Console device only; the web properties (aerinmedical.com, vivaer.com, rhinaer.com) and the anonymously readable site API are not named in scope. evidence: - source: https://aerinmedical.com/cybersecurity/ kind: disclosure-policy-page http_status: 200 fetched: '2026-07-31' - source: https://aerinmedical.com/compliance/ kind: compliance-index-listing http_status: 200 fetched: '2026-07-31' - source: /.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-07-31'