generated: '2026-08-23' method: searched probe: true source: https://impulse-dynamics.com/vulnerability-disclosure-program/ policy: - https://impulse-dynamics.com/vulnerability-disclosure-program/ contact: - mailto:productsecurity@impulsedynamics.com - mailto:infrastructuresecurity@impulsedynamics.com scope: >- The published program covers "medical devices, health software, and Impulse Dynamics' infrastructure" — a device-maker VDP rather than a web-application one. Two separate contacts are published and they are deliberately split by surface: product security handles products, solutions and services (the Optimizer implantable pulse generator family and its programmer/health software), infrastructure security handles corporate infrastructure. contacts: - role: Product Security scope: Products, Solutions, and Services email: productsecurity@impulsedynamics.com pgp_fingerprint: 352E ECA7 1DE6 FAE5 2296 AD62 DE8D 942B FBC4 8AB7 - role: Infrastructure Security scope: Corporate Infrastructure email: infrastructuresecurity@impulsedynamics.com pgp_fingerprint: 68F3 7CD0 246C E4B6 9402 0D3F 5BCB 0A7F 59B2 03B5 encrypted_submission: true pgp: >- Both contacts publish a PGP public key and fingerprint on the disclosure page, and the policy requires proof-of-concept or exploit code to be "clearly marked as such and encrypted with our PGP key". safe_harbor: true safe_harbor_terms: >- Impulse Dynamics undertakes not to pursue legal action against researchers who test without harming the company or its customers, obtain permission/consent from customers before testing, follow the terms of any agreements entered into, and refrain from disclosing vulnerability details before a mutually agreed timeframe expires. Social engineering, creating backdoors, excessive data access and brute-force attacks are explicitly out of bounds. bug_bounty: false bug_bounty_note: >- No monetary bounty is offered. The published reward is attribution: "Researchers who submit a vulnerability report to us will be given full credit on our website once the submission has been accepted and validated." No HackerOne, Bugcrowd or Intigriti program was found for this company. coordinated_disclosure: accepts_coordinators: true named: [ICS-CERT, CERT/CC, NCSC] note: >- Reporters communicating with a vulnerability coordinator are asked to advise Impulse Dynamics and supply the coordinator tracking number. ICS-CERT being named first is consistent with a medical-device manufacturer operating under FDA premarket and postmarket cybersecurity expectations. security_txt: false security_txt_note: >- The policy is published only as an HTML page. https://impulse-dynamics.com/.well-known/security.txt returned HTTP 404 on 2026-08-23, so an automated scanner following RFC 9116 finds nothing even though a real, detailed program exists. Publishing a security.txt naming https://impulse-dynamics.com/vulnerability-disclosure-program/ as Policy and the two addresses as Contact would make this program machine-discoverable at zero cost. evidence: - source: https://impulse-dynamics.com/vulnerability-disclosure-program/ kind: disclosure page http_status: 200 fetched: '2026-08-23' keywords: [vulnerability disclosure, safe harbor, PGP, responsible disclosure, ICS-CERT] - source: https://impulse-dynamics.com/.well-known/security.txt kind: security.txt (negative probe) http_status: 404 fetched: '2026-08-23'