Responsible Disclosure Policy

Last updated on
August 14, 2026

CrowdHealth takes the security of our members' data seriously. If you believe you've found a security vulnerability in our systems, we want to hear from you.

Scope

This policy covers:

Out of scope

We will not respond to reports that are:

  • Automated scanner output with no proof of concept or demonstrated impact
  • Missing security headers, SPF/DKIM/DMARC findings, or other best-practice-only observations with no exploit
  • Clickjacking on pages with no sensitive actions
  • Self-XSS, or attacks requiring physical access to a user's device
  • Social engineering, phishing, or physical attacks against staff or facilities
  • Denial-of-service or load testing of any kind
  • Findings in third-party services we don't control

What we need from a report

Include clear steps to reproduce, the impact you've demonstrated, and any proof-of-concept material. Reports without reproduction steps and demonstrated impact will be closed without response.To confirm you've read this policy, include the phrase "crowdhealth-disclosure-ack" somewhere in your first message.

Rewards

For valid, in-scope reports that are reproducible and demonstrate a genuine security impact, we determine bounty rewards based on historical public payouts from established bug bounty platforms and industry standards. This means we reference what comparable vulnerabilities have been publicly rewarded at similar organizations to ensure our payouts are fair and aligned with market norms.

Safe harbor

If you make a good-faith effort to comply with this policy while researching a vulnerability, we will not pursue legal action against you. Please:

  • Avoid accessing, modifying, or deleting data beyond what's needed to demonstrate an issue
  • Give us a reasonable amount of time to fix the issue before any public disclosure
  • Don't degrade the availability of our services

How to report

Email security@joincrowdhealth.com. We aim to acknowledge reports within 5 business days.