← Trust Center

Responsible disclosure

Responsible disclosure

We welcome reports from security researchers. If you have found a vulnerability in SwiftCode, this page explains how to report it, what we ask in return, and what you can expect from us.

Report a vulnerability

Email us and we will take it from there.

  • Email security@swiftcode.tech.
  • If possible, include clear steps to reproduce the issue.
  • Describe the impact and any affected endpoints, apps, or accounts.
  • Include supporting detail such as request/response samples where relevant.

What we ask of researchers

Good-faith research protects patients and staff. Please keep testing safe and private.

  • Report privately and give us reasonable time to remediate before any public disclosure.
  • Do not access, modify, or delete data that is not yours.
  • Do not run denial-of-service tests or automated scanning that degrades service.
  • Do not use social engineering or physical attacks against our people or facilities.

Our response process

We treat reports seriously and keep you informed as we work.

  • We acknowledge your report when we receive it.
  • We triage and assess severity.
  • We remediate based on severity and impact.
  • We keep you informed through the process.

This describes our process rather than a fixed service-level commitment; timelines depend on severity and complexity.

Safe harbor

We support good-faith security research.

We will not pursue legal action for good-faith security research that follows this policy. If you are unsure whether an activity is authorized, contact us first at security@swiftcode.tech before proceeding.

Scope

Please focus on the assets below and steer clear of the out-of-scope categories.

In scope

  • swiftcode.tech web properties.
  • The SwiftCode applications and APIs.

Out of scope

  • Denial-of-service attacks.
  • Spam and social engineering.
  • Physical access attacks.
  • Findings that require a rooted / jailbroken device or physical device theft.
A machine-readable version of this policy is available at /.well-known/security.txt.

Evaluating SwiftCode for your facility?

Enterprise customers may request our security questionnaire, architecture overview, and pilot materials during procurement — under NDA where required.

Security questions? security@swiftcode.tech