At Medendo, the security of our systems and the data of our users is a top priority. We encourage the responsible disclosure of security vulnerabilities to help us ensure the safety and privacy of our users. If you discover a vulnerability, we appreciate your assistance in reporting it to us in a responsible manner.
Scope
This policy applies to vulnerabilities in any service or system owned and operated by Medendo, including but not limited to:
Safe Harbor
We will not take legal action against researchers who:
Your security research must comply with all applicable laws and regulations. You are authorized to test for vulnerabilities in systems covered under this policy, and we will not pursue legal action or report you to law enforcement as long as your actions are aligned with the rules in this policy.
How to Report a Vulnerability
If you identify a security vulnerability, please follow these steps:
What We Expect
What You Can Expect
Recognition and Incentives
While we do not offer a formal bug bounty program at this time, we are happy to publicly recognize individuals who responsibly disclose vulnerabilities. If you would like to be credited, please let us know, and we will list your name on our Security Hall of Fame.
No Compensation
At this time, we do not offer financial rewards for vulnerability disclosures. However, we greatly value your contribution to the security of our systems and are committed to improving our processes with your help.
What Not to Do
Legal Disclaimers
This policy is intended to provide legal protection for researchers who follow the guidelines. However, Medendo reserves the right to update or modify this policy at any time. By submitting a report, you agree to comply with this policy. Any actions outside the scope of this policy or the law may void the protections offered.
Thank you for helping us keep Medendo secure!