VetiCloud ← Home

Vulnerability Disclosure Policy

Effective from: 07.10.2026  ·  Last updated: 07.10.2026

1. Who this policy concerns

Wozniak Solutions sp. z o.o. with its registered office in Warsaw (02-703), ul. Bukowińska 24c/7, KRS 0000624966 (hereinafter: “we”), is the manufacturer of the VetiCloud system and of the applications, programs and devices supplied with it. We treat the security of the data of practices, their patients and pet owners as a priority. This policy describes how to report a vulnerability in our products to us and what the reporter can expect.

2. How to report a vulnerability

Report vulnerabilities to security (at) veticloud.com. This address is used solely for reporting vulnerabilities and security incidents — for questions about using the system, please use the support panel or the contact form. In your report, include:

  1. the name of the product and the version affected by the vulnerability (e.g. the page address, the version of the application or program);
  2. a description of the vulnerability and the steps to reproduce it and, if possible, a proof of concept;
  3. the possible impact and whether you are aware of the vulnerability being exploited by third parties;
  4. your contact details and whether you wish to be credited as the author of the report.

We accept reports in Polish and English. We also publish the reporting address and a link to this policy in the file https://veticloud.com/.well-known/security.txt.

3. What we do after receiving a report

  1. We confirm receipt of the report within 2 working days.
  2. Within 5 working days we provide an initial assessment: whether the report concerns a vulnerability, how severe it is and which versions it affects.
  3. We fix the vulnerability without undue delay. The time needed to prepare a fix depends on the severity of the vulnerability and the complexity of the change; we keep the reporter informed of progress.
  4. We provide security fixes free of charge and, where the product allows it, automatically.
  5. Once a fix is available, we inform the users affected by the vulnerability, together with recommendations on the actions they should take.

4. Coordinated disclosure

We ask that you refrain from publicly disclosing details of the vulnerability until a fix is available, but for no longer than 90 days from the report, unless we jointly agree on a different date. We agree the disclosure date with the reporter. If the vulnerability is being actively exploited, we may warn users earlier. With the reporter’s consent, we credit them as the author of the report in the information about the fixed vulnerability.

5. Rules for acting in good faith

We will not take legal action against a person who, in good faith and in accordance with this policy, searches for vulnerabilities and reports them to us. We ask you to:

  1. test only on your own account, your own device and data you are entitled to use;
  2. not access other people’s data, in particular the data of patients and pet owners, and in the event of accidental access — stop, not copy the data and describe this in the report;
  3. not modify or delete data and not exploit the vulnerability to a greater extent than is necessary to demonstrate it;
  4. not carry out denial-of-service attacks, social engineering or physical tests, and not send unsolicited messages;
  5. keep information about the vulnerability confidential until it has been fixed.

6. What we do not treat as vulnerabilities

We accept reports of low security significance, but fixing them may take longer. These include, in particular: results of automated scanners without a demonstrated real impact, the absence of individual security headers or e-mail DNS records without a demonstrated impact, attacks requiring physical access to the user’s unlocked device, and vulnerabilities occurring only in unsupported versions of browsers or operating systems. We do not run a programme of monetary rewards for reports.

7. Reports to authorities and suppliers

We report actively exploited vulnerabilities and severe incidents having an impact on the security of our products in accordance with Regulation (EU) 2024/2847 of the European Parliament and of the Council (Cyber Resilience Act) via the single reporting platform operated by ENISA, to CSIRT NASK as the coordinator in Poland. We also report vulnerabilities in components supplied by other entities to their developers. For this purpose, we may share information from the report with those entities to the extent necessary.

8. The reporter’s data

We process the reporter’s data for the purpose of handling the report, contacting them about it and fulfilling legal obligations, on the terms described in the Privacy Policy. We do not disclose the reporter’s data publicly without their consent.

9. Changes to the policy

We update the policy together with changes to our products and the law. Every version has an effective date, and previous versions remain available. The document has been drawn up in Polish; translations are for information purposes only.

This version is effective from 7 October 2026

Other documents