legacy-medical-device-security-frameworks

Security policy

Reporting a vulnerability

If you believe you have found a security issue in any artifact in this repository — particularly the MFA shim prototype or test harness — please do not open a public issue.

Instead, report privately by emailing the maintainers. Include:

The maintainers will acknowledge your report within seven days, work with you to understand and validate the issue, and coordinate a public disclosure timeline once a fix or mitigation is available.

Scope

This security policy applies to:

This security policy does not apply to:

Status

This is research output, not a regulated product. Vulnerability reports are addressed on a best-effort basis. There is no service-level agreement.