StellarQ

Coordinated vulnerability disclosure

StellarQ builds medical device software used in clinical care. If you have found a security weakness in it, we want to hear from you.

Report a vulnerability

English or Finnish. Anonymous reports accepted. Machine-readable contact details: security.txt

5 business days
We acknowledge your report.
15 business days
You receive our initial assessment, including whether we could reproduce the issue.
90 days
Target for resolving critical vulnerabilities. We tell you if we need longer.

1. Introduction

StellarQ Oy develops medical device software for use in clinical healthcare settings. The security and safety of our products is of paramount importance. We recognise that security researchers, healthcare professionals, and other parties may discover vulnerabilities in our software, and we are committed to working collaboratively with reporters to address them responsibly.

This Coordinated Vulnerability Disclosure (CVD) Policy describes how StellarQ Oy receives, assesses, and responds to vulnerability reports concerning our software products. It applies to all StellarQ Oy software products, including StellarQ Medical.

2. Scope

This policy applies to security vulnerabilities discovered in:

  • StellarQ Medical — the clinical decision support software module
  • StellarQ Clinic — the clinical data platform for structured patient health information management
  • StellarQ My — the patient-facing PROM mobile application
  • Any other software products developed and maintained by StellarQ Oy

Vulnerabilities in third-party components, infrastructure, or services that are outside StellarQ Oy's direct control should be reported to the respective vendor. StellarQ Oy will coordinate with third-party vendors where relevant.

3. Reporting a vulnerability

3.1. How to report

Send your report by email to security@stellarq.com. Reports may be submitted in English or Finnish. Our contact details are also published in machine-readable form at /.well-known/security.txt.

3.2. What to include

To help us assess and reproduce the vulnerability efficiently, please include as much of the following as possible:

  • A description of the vulnerability and its potential impact
  • The affected product and version, if known
  • Steps to reproduce the vulnerability
  • Any supporting evidence such as screenshots, logs, or proof-of-concept code
  • Your contact details if you wish to receive updates on the report

Reports may be submitted anonymously. Anonymous reporters will not be able to receive status updates.

3.3. Encryption

If you wish to submit your report in encrypted form, say so in an initial email to security@stellarq.com and we will agree a suitable encrypted channel with you before you send the details.

4. Our commitments to reporters

StellarQ Oy commits to the following upon receiving a vulnerability report:

  • Acknowledgement — we will acknowledge receipt of your report within 5 business days
  • Initial assessment — we will provide an initial assessment of the report, including whether we have been able to reproduce the vulnerability, within 15 business days of acknowledgement
  • Regular updates — we will keep you informed of the progress of our investigation and remediation at reasonable intervals
  • Transparency — we will notify you when the vulnerability has been resolved
  • Recognition — with your consent, we will acknowledge your contribution in the relevant security advisory or release notes
Safe harbour
StellarQ Oy will not pursue legal action against reporters who discover and report vulnerabilities in good faith in accordance with this policy.

5. Our assessment and response process

Upon receiving a vulnerability report, StellarQ Oy will:

  1. Acknowledge receipt to the reporter within 5 business days
  2. Assess the vulnerability for its potential impact on patient safety, data confidentiality, and product integrity
  3. Prioritise the response based on severity — vulnerabilities with potential patient safety impact are treated as critical and escalated immediately to the CTO and PRRC
  4. Remediate the vulnerability — the timeline depends on severity and complexity; critical vulnerabilities affecting patient safety are prioritised for immediate remediation
  5. Verify that the remediation is effective through testing
  6. Release a security update through the normal software release process
  7. Notify the reporter that the vulnerability has been resolved

For vulnerabilities assessed as having potential patient safety impact, StellarQ Oy will additionally evaluate whether a field safety corrective action or vigilance report is required under EU MDR 2017/745.

6. Responsible disclosure

StellarQ Oy requests that reporters:

  • Allow us reasonable time to assess and remediate the vulnerability before public disclosure
  • Avoid accessing, modifying, or deleting data beyond what is necessary to demonstrate the vulnerability
  • Avoid actions that could harm the availability or integrity of our services or patient data
  • Do not disclose the vulnerability to third parties before StellarQ Oy has had the opportunity to remediate it

StellarQ Oy aims to resolve critical vulnerabilities within 90 days of the initial report. If remediation requires more time, we will communicate this to the reporter and agree a reasonable extended timeline before public disclosure.

7. Out of scope

The following are outside the scope of this policy:

  • Social engineering or phishing attacks targeting StellarQ Oy personnel
  • Physical security vulnerabilities
  • Denial of service attacks
  • Vulnerabilities in third-party services or infrastructure not under StellarQ Oy's direct control
  • Reports generated solely by automated scanning tools without manual validation

8. Contact

Email

security@stellarq.com

Postal address

StellarQ Oy

Eerikinkatu 3 A

20100 Turku

Finland

9. Policy availability and review

This page publishes the current approved version of StellarQ Oy's Coordinated Vulnerability Disclosure Policy and is the authoritative rendering. A Finnish-language summary covers the reporting channel, our response commitments, and what we ask of reporters; this English page carries the full text.

The reporting channel security@stellarq.com is also referenced in the Instructions for Use accompanying StellarQ medical device software products.

This policy is reviewed annually and updated as needed to reflect changes in products, regulatory requirements, or industry best practice.

ISMS-POL-CVD-001-EN · Version 1.0 · Last updated 18 Aug 2026

StellarQ

StellarQ Oy

Eerikinkatu 3 A, 20100 Turku, FINLAND