Coordinated Vulnerability Disclosure Policy

Hyperfine, Inc.
Policy Publication Date: August 13, 2026

Products in scope: Swoop® Portable MR Imaging® System (“Swoop system”)

1. Purpose

Hyperfine, Inc. (“Hyperfine”) takes the security of our medical device and connected systems seriously. This policy describes how security researchers, clinicians, customers, and the public can report suspected vulnerabilities, and what to expect from us in return. It is aligned with ISO/IEC 29147, ISO/IEC 30111, and the U.S. FDA's Section 524B post-market cybersecurity expectations.

2. Scope

In scope:

Out of scope:

  • Social engineering of Hyperfine’s staff.
  • Physical attacks against Hyperfine’s facilities.
  • Findings that require root or physical access already granted to the reporter.
  • Issues in third-party services we do not operate.
  • Hyperfine’s public websites.
  • Any activities that may adversely affect Hyperfine’s systems availability, including denial of service (DoS) tests or attacks.
  • Intentional exploitation of a discovered vulnerability or the copying, downloading, or exfiltration of any of Hyperfine’s data. If you inadvertently access or receive Hyperfine’s data when discovering a vulnerability, you must retain only the minimum data necessary to report your discovery, explain the data and how you received it in your report, avoid copying or further disclosing the data, and follow any data destruction instructions that Hyperfine provides.

3. How to report

Send reports to security@hyperfine.io (PGP encryption available on request) or submit through the product support request form at https://www.hyperfinemri.com/request-support.

Please include:

  • Affected product and version (or URL / API endpoint), including Swoop system serial number or identifier.
  • Date and time, including duration if relevant, when the issue was encountered or discovered.
  • Reproduction steps, proof-of-concept, or supporting artifacts.
  • Your assessment of impact (data confidentiality, integrity, availability).
  • Your name or handle
  • Whether you want public credit or wish to remain anonymous.
  • Any other relevant information.

4. Rewards

Hyperfine does not provide any rewards, e.g., bug bounties, for finding/reporting issues.

5. Our commitments

Hyperfine strives to meet the following response times:

  • Acknowledge receipt within 3 business days.
  • Provide an initial triage decision within 10 business days.
  • Target remediation of confirmed exploitable vulnerabilities within 90 days.
  • Coordinate public disclosure within 90 days of a fix being available.
  • Report applicable vulnerabilities to the FDA, CISA, and customers in line with our post-market obligations under FDA Section 524B.

6. Safe harbor

Hyperfine will work with researchers to understand and resolve issues, and will not pursue civil action or report researchers to law enforcement for security research that:

  • Adheres to this policy in good faith.
  • Avoids privacy violations, data destruction, and service degradation.
  • Stops once a vulnerability is confirmed and reports it promptly.
  • Does not exploit any vulnerability beyond what is necessary to demonstrate it.

7. Public disclosure

Hyperfine prefers coordinated disclosure and welcomes collaboration from researchers and intermediaries. Please contact us to collaborate in the publication process. We will work with a reporter on a joint advisory, request a CVE when appropriate, and credit the reporter unless they ask to remain anonymous. The Hyperfine security team shall ensure the relevant technology owners develop and publish an appropriate advisory to customers and other external stakeholders as part of their resolution action plans. Public notification of security advisories is available at https://www.hyperfinemri.com/security-advisories.

8. Intellectual Property Rights to Reports and Related Materials

When you report a potential vulnerability and provide any related materials to us, you both:

  • Warrant that the report and any related materials you provide to us do not violate any third party's intellectual property rights.
  • Grant Hyperfine a non-exclusive, irrevocable, royalty-free, worldwide, perpetual license to use, reproduce, distribute, and create derivative works of the report and any related materials you provide.

9. Contact

Security contact: security@hyperfine.io

This policy is reviewed at least annually and updated as our products and regulatory obligations evolve.