Skip to content
Doctalis
Lire en françaisBack to Doctalis

Coordinated disclosure

Security policy

How to report a potential vulnerability affecting Doctalis safely.

Last updated 29 July 2026
PrivacyTermsLegal noticeCookiesSecurity

1. Reporting channel

Send reports to [email protected] with the subject “[SECURITY] Doctalis”, or use this page as the Contact URL published in security.txt. Include the affected URL, impact, minimal reproduction and a safe way to contact you.

Do not include patient data, session cookies, access tokens, private keys or a full production database extract. Redact evidence and provide sensitive material only after we agree on a protected channel.

2. In scope

Good-faith reports concerning doctalis.com, app.doctalis.com or api.doctalis.com are welcome when they use your own account and synthetic records and minimise traffic and impact.

3. Boundaries

Please do not:

  • access, alter, retain or disclose another person’s or practice’s data;
  • use real patient information, social engineering, phishing, physical attacks or employee targeting;
  • perform denial-of-service, load, spam, destructive, persistence or malware actions;
  • continue testing after you have enough evidence to demonstrate the issue;
  • publish details before a reasonable remediation and coordination period.

4. Our response

We will triage good-faith reports, seek clarification where needed and coordinate remediation and disclosure according to risk. This policy does not promise a bounty or payment. Any reward requires a separate written agreement.

5. Safe research

Research that stays within this policy, applicable law and the minimum necessary proof will not be treated as an attempt to harm Doctalis. This statement does not authorise testing of third-party services or data and cannot bind third parties.

6. Emergencies and support

This channel is not for medical emergencies, patient support or urgent clinical decisions. Contact the responsible healthcare professional or local emergency service for those matters.

Official references

  • IETF — RFC 9116 security.txt standard

© 2026 CodHash Agency Ltd · Doctalis

Contact: [email protected]