How to report a vulnerability, what we commit to, and our safe-harbour terms for good-faith research.
Our position
If you have found a vulnerability in SuperHIPAA, we want to hear about it — directly, quickly, and without you needing a lawyer first. Security research done in good faith makes the product safer for every customer, and a vendor that responds to disclosure with threats is advertising exactly how it will respond to a real incident. This page sets out how to report, what we commit to in return, and the safe-harbour terms that protect good-faith research.
How to report
Send reports to security@superhipaa.com (a PGP key is available on request if you prefer to encrypt your report). A useful report includes:
- The affected endpoint, component, or behaviour
- Steps to reproduce, as specific as you can make them
- The impact as you understand it — what an attacker could actually do
- Any proof-of-concept material, kept to the minimum needed to demonstrate the issue
You do not need a polished write-up. A rough email that lets us reproduce the problem beats a beautiful PDF that arrives a week later.
What we commit to
- We acknowledge every report within 2 business days.
- We work to a 90-day coordinated disclosure window, and we will agree an extension with you if remediation genuinely needs longer.
- We will not pursue legal action against security research conducted in good faith within the terms on this page.
Beyond the specific commitments above, our working process for every valid report is: acknowledge receipt, triage and confirm, keep you informed while we fix, and credit you when it is resolved — publicly if you want credit, silently if you prefer. We do not sit on reports, and we do not go quiet once we have what we need.
Safe harbour
We will not pursue legal action, and will not refer you to law enforcement, for security research conducted in good faith within these terms. Good faith means, concretely:
- You make a genuine effort to avoid privacy violations, data destruction, and service degradation.
- You access only the minimum data needed to demonstrate the vulnerability, and you do not retain, copy, or share customer data — this is a HIPAA-regulated service, and ePHI exposure is the line that must not be crossed.
- You give us reasonable time to remediate before any public disclosure.
- You do not use social engineering, physical intrusion, or attacks on our employees as part of the research.
If you are ever unsure whether something falls inside these terms, ask before you do it. We answer those questions quickly and without prejudice.
Scope
In scope: the SuperHIPAA application, API, and infrastructure we operate (www.superhipaa.com, the application and API domains we run, and the AWS environment behind them). Out of scope: third-party services we use but do not operate (report those to the vendor concerned), denial-of-service testing, spam, and findings that require an already-compromised device or account. Volume-scanner output submitted without analysis will be triaged, but a report that shows understanding of actual impact will always be treated with more urgency.
What happens to your report internally
Valid reports enter the same incident and vulnerability management process as internally discovered issues: severity-rated, assigned an owner, and tracked to closure against defined remediation timelines. If a report reveals that customer data was exposed, our incident response and breach notification obligations take over — reporter confidentiality is respected, but customer notification is never suppressed to protect our reputation. That ordering of priorities is the whole point of a trust page.
Documentation available on request
- SOC 2 Type II report (under NDA)
- Penetration test summary
- Business Associate Agreement
- Architecture and data flow diagram
- Completed CAIQ / SIG Lite
Questions
Security questions go to security@superhipaa.com and get a human answer within one business day. That includes questions about this policy itself — if any term here is ambiguous enough to make a researcher hesitate, we would rather clarify it than lose the report.