Version: 1.0
Date: 31 July 2026
Owner: Risto Anton Päärni, Founder, CEO
Applies to: DWS IQ Platform, Lifetime Oy
1. Introduction
At Lifetime Oy, the security of the systems behind the DWS IQ Platform is a top priority. However hard we work at it, vulnerabilities can never be completely eliminated. When a vulnerability is identified and exploited, it puts at risk the confidentiality, integrity, or availability of our systems and the information processed within them — including our customers’ data.
This policy describes which systems and types of testing are authorised, how to send us a vulnerability report, and what you can expect from us in return. We encourage security researchers to contact us and report potential issues by following this policy.
2. Authorisation & Safe Harbor
If you make a good-faith effort to identify and report a vulnerability while complying with this policy, we will work with you to understand and resolve the issue quickly, and we will not pursue legal action against you for that research. This safe harbor does not extend to testing outside the scope below, or to any activity listed under “Guidelines” and “Prohibited actions” as out of bounds.
3. Scope
This policy applies to:
- dws10.com and its public pages and endpoints
- dws6.com
- onelifetime.world
- Public API endpoints exposed by the above
- MCP (Model Context Protocol) servers exposed by the above
Any service not expressly listed above is out of scope and not authorised for testing. Vulnerabilities found in third-party vendor systems we integrate with (for example, cloud infrastructure, payment processors, or embedded widgets) are also out of scope for this policy — please report those directly to the vendor under their own disclosure policy.
4. Guidelines
While carrying out your research, you must:
- not take advantage of a vulnerability beyond what is necessary to demonstrate it — for example, do not download more data than needed, and do not delete or modify other people’s data
- only use harmless, non-destructive methods to confirm a vulnerability is present
- not reveal any data accessed during your research to the public or any third party
- not disclose the vulnerability to the public or any third party until we have resolved it
- stop testing immediately and notify us right away if you encounter any sensitive information (personal data, financial, health, proprietary, or trade-secret information), and not disclose that data to anyone else
Do not
- place malware (virus, worm, trojan, etc.) on any system
- compromise a system to gain full or partial control
- copy, modify, or delete data on a system
- make changes to a system
- repeatedly access a system or share access with anyone else
- use access obtained through one issue to attempt to reach other systems
- change the access rights of other users
- use automated scanning tools against our systems
- use brute-force attacks
- use denial-of-service attacks or social engineering (phishing, vishing, spam, etc.)
- attack our physical security
5. Reporting a Vulnerability
What we would like to see from you
If you have identified a vulnerability, please:
- email your findings to security@lifetime.fi, and let us know whether you agree to being credited by name or pseudonym as the discoverer
- provide enough information to reproduce the problem — typically the affected URL or endpoint and a description of the vulnerability are enough, though complex issues may need more technical detail or proof-of-concept code
- report in English or Finnish
No PGP key is published yet. If your finding is highly sensitive, say so in your initial email and we will agree an alternative secure channel with you before you send further detail.
What you can expect from us
In return, when you report a vulnerability to us, we will:
- acknowledge your report within 48 hours
- handle your report with strict confidentiality
- work to a severity-based fix timeline: Critical — 48 hours; High — 7 days; Medium — 30 days; Low — next release cycle
- where possible, let you know once the vulnerability has been remedied
- process any personal data you provide (such as your name and e-mail address) in line with applicable data protection law, and not pass your details to any third party without your permission
- credit you as the discoverer, by name or pseudonym, if you agreed to this in your initial report
6. More Information
See our security.txt (RFC 9116) for the machine-readable version of our security contact, and the DWS IQ Trust Center for an overview of our security controls and certification status. For KYA governance framework details (agent identity, board oversight, performance guarantees), see the Board Governance & D&O Safe Harbor section of the Legal Hub.
7. Contact and Questions
Report a vulnerability:
Email:
security@lifetime.fi
Policy owner:
Risto Anton Päärni, Founder, CEO, Lifetime Oy
Email:
risto.paarni@lifetime.fi
Document history:
2026-07-31: v1.0 — Initial policy published, adapted from the European Commission's
public vulnerability disclosure policy
Next review: 2026-10-31 (quarterly)