CrowdHealth takes the security of our members' data seriously. If you believe you've found a security vulnerability in our systems, we want to hear from you.
Scope
This policy covers:
- app.joincrowdhealth.com
- CrowdHealth Mobile—iOS, Android (
com.cratebind.crowdhealth)
Out of scope
We will not respond to reports that are:
- Automated scanner output with no proof of concept or demonstrated impact
- Missing security headers, SPF/DKIM/DMARC findings, or other best-practice-only observations with no exploit
- Clickjacking on pages with no sensitive actions
- Self-XSS, or attacks requiring physical access to a user's device
- Social engineering, phishing, or physical attacks against staff or facilities
- Denial-of-service or load testing of any kind
- Findings in third-party services we don't control
What we need from a report
Include clear steps to reproduce, the impact you've demonstrated, and any proof-of-concept material. Reports without reproduction steps and demonstrated impact will be closed without response.To confirm you've read this policy, include the phrase "crowdhealth-disclosure-ack" somewhere in your first message.
Rewards
For valid, in-scope reports that are reproducible and demonstrate a genuine security impact, we determine bounty rewards based on historical public payouts from established bug bounty platforms and industry standards. This means we reference what comparable vulnerabilities have been publicly rewarded at similar organizations to ensure our payouts are fair and aligned with market norms.
Safe harbor
If you make a good-faith effort to comply with this policy while researching a vulnerability, we will not pursue legal action against you. Please:
- Avoid accessing, modifying, or deleting data beyond what's needed to demonstrate an issue
- Give us a reasonable amount of time to fix the issue before any public disclosure
- Don't degrade the availability of our services
How to report
Email security@joincrowdhealth.com. We aim to acknowledge reports within 5 business days.