Vulnerability Disclosure Policy
PracticeRunner welcomes responsible reports of potential security vulnerabilities. If you believe you have found an issue, email [email protected]. Please provide enough detail for us to reproduce, investigate, and address the issue.
Reporting a vulnerability
Please include:
- The affected URL or feature
- The vulnerability type
- Steps to reproduce the issue
- The potential impact
- Screenshots, request and response details, or a proof of concept when helpful
- Whether you accessed any sensitive data
Do not include PHI, client records, credentials, or other sensitive information in your email. Describe what you encountered without copying the data whenever possible.
Research guidelines
When investigating a potential vulnerability:
- Do not access, modify, download, retain, disclose, or otherwise interact with another user's data beyond what is strictly necessary to demonstrate the issue.
- Do not deliberately access PHI or other sensitive client or patient information.
- Do not perform destructive testing.
- Do not perform denial-of-service or load testing.
- Do not use social engineering or phishing.
- Do not use automated testing that could materially degrade the production service.
- Do not establish persistence, move laterally, expand privileges beyond what is necessary to demonstrate the vulnerability, or attempt to maintain access.
If you encounter real user data or sensitive information, stop testing and report the issue immediately.
Safe harbor
If you make a good-faith effort to follow this policy, avoid harm, and report vulnerabilities promptly, PracticeRunner will treat your research as authorized under this policy to the extent we are able to do so. This policy does not provide immunity from laws or actions outside PracticeRunner's control.
No paid bug bounty
PracticeRunner does not currently operate a paid bug bounty program. Submitting a vulnerability report does not create an entitlement to compensation.
