Responsible disclosure
Responsible disclosure
We welcome reports from security researchers. If you have found a vulnerability in SwiftCode, this page explains how to report it, what we ask in return, and what you can expect from us.
Report a vulnerability
Email us and we will take it from there.
- Email security@swiftcode.tech.
- If possible, include clear steps to reproduce the issue.
- Describe the impact and any affected endpoints, apps, or accounts.
- Include supporting detail such as request/response samples where relevant.
What we ask of researchers
Good-faith research protects patients and staff. Please keep testing safe and private.
- Report privately and give us reasonable time to remediate before any public disclosure.
- Do not access, modify, or delete data that is not yours.
- Do not run denial-of-service tests or automated scanning that degrades service.
- Do not use social engineering or physical attacks against our people or facilities.
Our response process
We treat reports seriously and keep you informed as we work.
- We acknowledge your report when we receive it.
- We triage and assess severity.
- We remediate based on severity and impact.
- We keep you informed through the process.
This describes our process rather than a fixed service-level commitment; timelines depend on severity and complexity.
Safe harbor
We support good-faith security research.
We will not pursue legal action for good-faith security research that follows this policy. If you are unsure whether an activity is authorized, contact us first at security@swiftcode.tech before proceeding.
Scope
Please focus on the assets below and steer clear of the out-of-scope categories.
In scope
- swiftcode.tech web properties.
- The SwiftCode applications and APIs.
Out of scope
- Denial-of-service attacks.
- Spam and social engineering.
- Physical access attacks.
- Findings that require a rooted / jailbroken device or physical device theft.
Evaluating SwiftCode for your facility?
Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.
Security questions? security@swiftcode.tech