Coordinated Vulnerability Disclosure (CVD)
We welcome responsible security research and follow a coordinated vulnerability disclosure process. WSA values the work done by security researchers and encourages proactive engagement and coordination with us on newly discovered security vulnerabilities in a responsible manner. Our CVD process sets expectations between WSA and the researcher reporting potential security vulnerabilities. Our goal should always be to reduce security risk within products to an acceptable level.
If you believe you’ve found a vulnerability:
-
- Email: cvd@wsa.com
- Subject line: “Potential vulnerability in hearing device ecosystem”
- Include: Product name, version, a technical description, and any proof‑of‑concept steps.
Our process:
- Acknowledge receipt: We confirm we’ve received your report.
- Assess impact: Our product security team investigates and validates the issue.
- Mitigate and fix: We develop and test a remediation or mitigation.
- Coordinate disclosure: When appropriate, we coordinate public communication with you and relevant stakeholders.
- Acknowledge researcher: Give credit to the researcher on our public facing web-site after the completion of a successful public disclosure (Follows the WSA CVD process).
Reporting Prerequisites:
- Comply with all applicable laws and regulations in which the WSA product is located.
- Do not include sensitive information, e.g., patient information, in any communication you provide us.
- Do not exploit vulnerabilities or similar testing on products that are in active use.
- In the spirit of responsible disclosure, we encourage you to work with WSA on public disclosure details, e.g., date of public disclosure and draft of disclosure details being released to the public.
Our Product Security Incident Response Team (PSIRT):
- Monitors for new threats and vulnerabilities affecting our products.
- Coordinates technical response, risk assessment, and remediation.
- Communicates with regulators, healthcare providers, and customers when needed.