Responsible Disclosure
Found a vulnerability? Here is what we promise, and what we ask.
1.Our commitment to you
We will not pursue legal action, or ask anyone else to, for good-faith security research that follows this policy. We will acknowledge your report within three business days, tell you our assessment of severity, keep you updated until it is closed, and credit you publicly if you want that and decline if you do not.
2.In scope
- This website.
- The Revitics application and its API.
- The public demonstration environment, which contains synthetic data only.
Out of scope: anything belonging to our customers, our subprocessors' infrastructure, physical security, and social engineering of our staff or customers.
3.What we ask
- Use the demonstration environment. Its credentials are published and its data is synthetic, so you can be thorough without touching anything real.
- Stop if you reach real patient data. Do not download it, do not explore further, tell us immediately. This matters more than the finding.
- No denial of service, no volumetric testing, no destruction or modification of data.
- Give us reasonable time to fix it before publishing — ninety days is our expectation, and we will tell you if we need longer and why.
4.How to report
Email the security address at the foot of this page. Include steps to reproduce, what you were able to access, and anything you think we would get wrong about the impact.
A report that a scanner produced, with no evidence of exploitability, is not a vulnerability report — we will read it, but it will not get the same response.
5.Bounty
NEEDS DECISION There is no paid bounty programme today. Whether to run one, and at what amounts, is a decision for the company. We say so rather than leaving researchers to guess.
Questions about this document: · All policies