← Back to Compliance Hub

Version: 1.0
Date: 31 July 2026
Owner: Risto Anton Päärni, Founder, CEO
Applies to: DWS IQ Platform, Lifetime Oy

1. Introduction

At Lifetime Oy, the security of the systems behind the DWS IQ Platform is a top priority. However hard we work at it, vulnerabilities can never be completely eliminated. When a vulnerability is identified and exploited, it puts at risk the confidentiality, integrity, or availability of our systems and the information processed within them — including our customers’ data.

This policy describes which systems and types of testing are authorised, how to send us a vulnerability report, and what you can expect from us in return. We encourage security researchers to contact us and report potential issues by following this policy.

2. Authorisation & Safe Harbor

If you make a good-faith effort to identify and report a vulnerability while complying with this policy, we will work with you to understand and resolve the issue quickly, and we will not pursue legal action against you for that research. This safe harbor does not extend to testing outside the scope below, or to any activity listed under “Guidelines” and “Prohibited actions” as out of bounds.

3. Scope

This policy applies to:

Any service not expressly listed above is out of scope and not authorised for testing. Vulnerabilities found in third-party vendor systems we integrate with (for example, cloud infrastructure, payment processors, or embedded widgets) are also out of scope for this policy — please report those directly to the vendor under their own disclosure policy.

4. Guidelines

While carrying out your research, you must:

Do not

5. Reporting a Vulnerability

What we would like to see from you

If you have identified a vulnerability, please:

No PGP key is published yet. If your finding is highly sensitive, say so in your initial email and we will agree an alternative secure channel with you before you send further detail.

What you can expect from us

In return, when you report a vulnerability to us, we will:

6. More Information

See our security.txt (RFC 9116) for the machine-readable version of our security contact, and the DWS IQ Trust Center for an overview of our security controls and certification status. For KYA governance framework details (agent identity, board oversight, performance guarantees), see the Board Governance & D&O Safe Harbor section of the Legal Hub.

7. Contact and Questions

Report a vulnerability:
Email: security@lifetime.fi

Policy owner:
Risto Anton Päärni, Founder, CEO, Lifetime Oy
Email: risto.paarni@lifetime.fi


Document history:
2026-07-31: v1.0 — Initial policy published, adapted from the European Commission's public vulnerability disclosure policy
Next review: 2026-10-31 (quarterly)