1. Reporting channel
Send reports to [email protected] with the subject “[SECURITY] Doctalis”, or use this page as the Contact URL published in security.txt. Include the affected URL, impact, minimal reproduction and a safe way to contact you.
Do not include patient data, session cookies, access tokens, private keys or a full production database extract. Redact evidence and provide sensitive material only after we agree on a protected channel.
2. In scope
Good-faith reports concerning doctalis.com, app.doctalis.com or api.doctalis.com are welcome when they use your own account and synthetic records and minimise traffic and impact.
3. Boundaries
Please do not:
- access, alter, retain or disclose another person’s or practice’s data;
- use real patient information, social engineering, phishing, physical attacks or employee targeting;
- perform denial-of-service, load, spam, destructive, persistence or malware actions;
- continue testing after you have enough evidence to demonstrate the issue;
- publish details before a reasonable remediation and coordination period.
4. Our response
We will triage good-faith reports, seek clarification where needed and coordinate remediation and disclosure according to risk. This policy does not promise a bounty or payment. Any reward requires a separate written agreement.
5. Safe research
Research that stays within this policy, applicable law and the minimum necessary proof will not be treated as an attempt to harm Doctalis. This statement does not authorise testing of third-party services or data and cannot bind third parties.
6. Emergencies and support
This channel is not for medical emergencies, patient support or urgent clinical decisions. Contact the responsible healthcare professional or local emergency service for those matters.