Responsible Disclosure

We appreciate security researchers who help us protect patient data. We commit to responding quickly, acting in good faith, and not pursuing legal action for responsible reports.

Fast Response

We acknowledge every report within 24 hours and provide an initial assessment within 5 business days. Critical vulnerabilities are triaged within 4 hours.

🤝

Good Faith

We will not pursue legal action against researchers who follow responsible disclosure guidelines and do not access, modify, or exfiltrate patient data.

🏆

Recognition

Researchers who report valid vulnerabilities will be acknowledged in our security hall of fame (with consent) and may be eligible for recognition rewards.

⚠️
Healthcare data sensitivity — CareSphere stores protected health information. If you believe you have accessed any PHI during your research, stop immediately and report without retaining any data. We take patient privacy extremely seriously and will work with you to assess scope.
🎯

Scope

What we do and don't want you to test

✓ In Scope

  • CareSphere web application (caresphere.ai/*)
  • CareSphere REST API (/api/*)
  • Authentication and session management
  • Access control bypass or privilege escalation
  • SQL injection or data exposure vulnerabilities
  • Cryptographic weaknesses in token generation
  • CORS, CSP, or security header misconfigurations
  • IoT device authentication weaknesses (test devices only)

✗ Out of Scope

  • Social engineering attacks on employees
  • Physical access to facilities or devices
  • Denial of service (DoS/DDoS) attacks
  • Automated scanning that generates excessive load
  • Reports on production systems with real patient data
  • Third-party services we don't control (AWS console, Cognito hosted UI)
  • Best-practice recommendations without demonstrated impact
⏱️

Response SLA

Our commitment by severity level

Severity Examples Acknowledgement Initial Assessment Target Fix
Critical PHI data exposure, auth bypass, RCE 4 hours Same day 48 hours
High Privilege escalation, SQL injection, XSS with PHI access 24 hours 2 business days 7 days
Medium IDOR, CSRF, sensitive info in logs 24 hours 5 business days 30 days
Low Missing security headers, minor info disclosure 48 hours 10 business days 90 days
✉️

Submit a Report

Use the form below or email security@spiritify.ai directly

We'll use this to coordinate disclosure. We never share it publicly without consent.
Include affected endpoint/component, steps to reproduce, and observed vs expected behaviour. Do NOT include any patient data in your report.

By submitting you agree to act in good faith and not access, retain, or disclose any patient data encountered during research.