generated: '2026-08-17' method: searched source: https://www.heartfocus.ai/security/cvd docs: https://www.heartfocus.ai/security/cvd note: >- Found by walking the sitemap, not by the standard probe. The automated probe-security-programs.py pass reported vdp=none because DESKi does not use any of the usual locations — /security is a real 404, there is no /.well-known/security.txt, and there is no /responsible-disclosure. The policy lives one level down at /security/cvd and is listed in https://www.heartfocus.ai/sitemap.xml. program: published: true name: Coordinated Vulnerability Disclosure (CVD) url: https://www.heartfocus.ai/security/cvd scope: >- Reporting of potential cybersecurity vulnerabilities in DESKi products and services. Explicitly NOT for technical support, adverse events or quality complaints. bug_bounty: false platform: null safe_harbor: false contact: email: security@deski.ai channel: email pgp: >- A public PGP key is referenced ("Please use email encryption with our public PGP key") but no key or fingerprint is published on the page and no /.well-known/security.txt carries an Encryption: field. corroboration: - source: dns-caa record: '0 iodef "mailto:security@deski.ai"' domain: heartfocus.ai note: The CAA iodef record names the same address, an independent confirmation. - source: product-documentation url: https://www.heartfocus.ai/user-manuals note: >- The HeartFocus v1.3.1 user manual (Chapter 6 - Cybersecurity) repeats the security@deski.ai address and links the CVD process at https://heartfocus.ai/security/cvd. researcher_requirements: - Actions must not put patient safety at risk - Comply with all applicable laws of the researcher's location and the location of the device - Obtain written permission from the product owner before beginning security testing - No public disclosure before a mutually agreed timeframe with DESKi - Products must be returned to their original state before clinical use - Reports in English where possible - Do not include PHI/PII or sample patient information in submissions submission_fields: - Contact information (name, address, phone number) - Date and method of discovery - Description of the potential vulnerability - Product name - Version number - Configuration details - Steps to reproduce - Tools and methods - Exploitation code - Privileges required - Results or impact response_commitments: acknowledgement: 2 business days process: - Acknowledge receipt within two business days - Investigate the potential vulnerability - Conduct risk analysis to determine appropriate action - Contact the submitter for additional information if needed - Provide the submitter a summary of findings throughout the process patch_notification: >- Security issues identified in the DESKi application, and their remediation guidance, are communicated by email to users with an active account (user manual, Chapter 6). terms: submitter_rights: >- Submissions are treated as non-proprietary and non-confidential; DESKi may use the information without restriction and the submission creates no rights for the submitter. security_officer: Kelly Porfirio (CRQO & CISO) x-evidence: fetched: '2026-08-17' url: https://www.heartfocus.ai/security/cvd http_status: 200 probed_misses: - url: https://www.heartfocus.ai/security status: 404 - url: https://www.heartfocus.ai/.well-known/security.txt status: 404 - url: https://deski.ai/.well-known/security.txt status: 404