Popular searches
- Iphone
- Samsung
- Xiaomi
- Airpod
T
Skip to contentUse code: 25OFF for 25% off your order today!
TRANSCEND INFORMATION SECURITY
OUR COMMITMENT
Transcend is committed to protecting the security and privacy of the information entrusted to us by patients, customers, healthcare providers, business partners, and employees.
Our products and services may include medical devices, mobile applications, desktop software, websites, cloud-based services, and support systems. We recognize that cybersecurity is an important component of product safety, data protection, and the continued availability of our products and services.
Transcend works to identify, evaluate, and address cybersecurity risks throughout the product lifecycle.
Coordinated Vulnerability Disclosure
Transcend values the contributions of security researchers, customers, healthcare professionals, and others who help identify potential cybersecurity vulnerabilities.
If you believe you have discovered a security vulnerability affecting a Transcend product, application, website, cloud service, or other Transcend-operated system, please report it to us as soon as possible.
How to Report Potential Vulnerability
Send your report to: security@mytranscend.com
Please include as much of the following information as possible:
• The affected product, software, application, service, domain, or device model.
• The product serial number, software version, firmware version, or application version, when relevant.
• A detailed description of the suspected vulnerability.
• The steps necessary to reproduce the issue.
• Relevant screenshots, logs, scripts, proof-of-concept code, or technical documentation.
• The potential security, privacy, operational, or patient-safety impact.
• Any actions already taken during testing.
• Your contact information, if you would like Transcend to provide follow-up information.
• Whether you intend to publicly disclose the vulnerability and any proposed disclosure timeline.
Do not include personal information, protected health information, therapy information, credentials, or other sensitive information that is not necessary for Transcend to investigate the report.
What You Can Expect
After receiving a vulnerability report, Transcend will make reasonable efforts to:
1. Acknowledge receipt of the report within five business days.
2. Assign the report a tracking or incident number.
3. Review the report and determine whether additional information is required.
4. Evaluate the potential cybersecurity, privacy, product-performance, and patient-safety impact.
5. Coordinate internally with appropriate engineering, quality, regulatory, privacy, and security personnel.
6. Develop and implement appropriate corrective or preventive actions when vulnerability is confirmed.
7. Coordinate the timing of any public disclosure with the person or organization that submitted the report, when appropriate.
8. Notify the reporter when the investigation has been completed or the confirmed issue has been addressed, subject to legal, regulatory, security, and confidentiality restrictions.
The time required to investigate and remediate vulnerability will depend on its complexity, severity, potential safety impact, affected products, and the availability of an appropriate mitigation.
Transcend may not be able to provide detailed information about an investigation when doing so could create additional security risks, disclose confidential information, or interfere with legal or regulatory obligations.
Guidelines for Security Research
To protect patients, customers, researchers, and Transcend systems, security research must be conducted responsibly and in good faith.
Researchers must:
• Test only systems, accounts, devices, and data they own or are expressly authorized to test.
• Make reasonable efforts to avoid privacy violations, service interruption, degradation of product performance, data loss, or harm to patients or users.
• Stop testing and notify Transcend immediately if protected health information, personal information, credentials, or other sensitive data are encountered.
• Limit access to the minimum information necessary to demonstrate vulnerability.
• Securely delete any Transcend information obtained during testing after the vulnerability has been reported and the investigation is complete.
• Allow Transcend a reasonable period to investigate and address the issue before making information public.
• Comply with all applicable laws and regulations.
Testing involving a Transcend medical device must not interfere with prescribed therapy, alter clinical settings without authorization, create unsafe operating conditions, or place a patient or other person at risk.
Prohibited Activities
The following activities are not authorized under this policy:
• Social engineering, phishing, impersonation, or fraudulent communications.
• Physical attacks against Transcend facilities, personnel, devices, or infrastructure.
• Denial-of-service or distributed denial-of-service testing.
• Brute-force attacks, credential stuffing, or excessive automated login attempts.
• Introducing malware, ransomware, destructive code, or persistent access mechanisms.
• Accessing, modifying, downloading, deleting, or disclosing information belonging to another person.
• Testing could interfere with the safety, essential performance, availability, or operation of a medical device.
• Changing prescribed therapy settings or attempting to control a device being used by a patient.
• Testing third-party products, services, or systems that are not operated by Transcend.
• Conducting high-volume automated scanning that could degrade system performance.
• Attempting to gain physical access to Transcend property or equipment.
• Extortion, threats, or demands for payment as a condition of withholding vulnerability information.
• Publicly disclosing an unresolved vulnerability before Transcend has had a reasonable opportunity to investigate and mitigate the issue.
If you are uncertain whether a proposed activity is permitted, contact Transcend before conducting the activity.
Good-Faith Security Research
Transcend considers security research to be conducted in good faith when it is performed in accordance with this policy, is intended to improve the security or safety of Transcend products and services, and avoids harm to Transcend, its customers, patients, employees, partners, and other parties.
When research is conducted in good faith and in accordance with this policy, Transcend will not recommend or pursue legal action against the researcher solely for the authorized security research.
This statement does not authorize activities that violate applicable laws, compromise patient safety, affect systems or information belonging to third parties, or fall outside the scope of this policy.
Systems Covered by This Policy
Unless otherwise stated, this policy applies to the following Transcend-operated products and services:
• Transcend websites and domains.
• The MySleepDash mobile application.
• Transcend-operated cloud services and application programming interfaces supporting MySleepDash.
• Transcend Desktop Software.
• Currently supported Transcend connected medical devices and associated firmware.
• Other systems expressly identified by Transcend as being within scope.
The following are outside the scope of this policy unless Transcend provides written authorization:
• Third-party websites, applications, hosting platforms, payment processors, app stores, or services.
• Products that have reached the end of support.
• Dealer, distributor, healthcare-provider, or supplier systems that are not operated by Transcend.
• Employee-owned devices or personal accounts.
• Physical facilities and physical security controls.
A vulnerability in an out-of-scope third-party system may still be reported to Transcend when it reasonably appears to affect the security or safety of a Transcend product or service.
Have an account?
to check in faster.