Fast Response
We acknowledge every report within 24 hours and provide an initial assessment within 5 business days. Critical vulnerabilities are triaged within 4 hours.
Good Faith
We will not pursue legal action against researchers who follow responsible disclosure guidelines and do not access, modify, or exfiltrate patient data.
Recognition
Researchers who report valid vulnerabilities will be acknowledged in our security hall of fame (with consent) and may be eligible for recognition rewards.
Scope
What we do and don't want you to test
✓ In Scope
- CareSphere web application (caresphere.ai/*)
- CareSphere REST API (/api/*)
- Authentication and session management
- Access control bypass or privilege escalation
- SQL injection or data exposure vulnerabilities
- Cryptographic weaknesses in token generation
- CORS, CSP, or security header misconfigurations
- IoT device authentication weaknesses (test devices only)
✗ Out of Scope
- Social engineering attacks on employees
- Physical access to facilities or devices
- Denial of service (DoS/DDoS) attacks
- Automated scanning that generates excessive load
- Reports on production systems with real patient data
- Third-party services we don't control (AWS console, Cognito hosted UI)
- Best-practice recommendations without demonstrated impact
Response SLA
Our commitment by severity level
| Severity | Examples | Acknowledgement | Initial Assessment | Target Fix |
|---|---|---|---|---|
| Critical | PHI data exposure, auth bypass, RCE | 4 hours | Same day | 48 hours |
| High | Privilege escalation, SQL injection, XSS with PHI access | 24 hours | 2 business days | 7 days |
| Medium | IDOR, CSRF, sensitive info in logs | 24 hours | 5 business days | 30 days |
| Low | Missing security headers, minor info disclosure | 48 hours | 10 business days | 90 days |
Submit a Report
Use the form below or email security@spiritify.ai directly