Vulnerability Disclosure Policy

Last updated: August 17, 2026

OneDose builds clinical decision support used by EMS providers in the field. We take the security of our platform seriously, and we welcome reports from security researchers who help us protect our customers and their patients. This policy explains how to report a vulnerability to us, what we ask of you, and what you can expect from us in return.

How to report

Send vulnerability reports to security@myonedose.com.

To help us assess and reproduce the issue quickly, please include:

Reports in English are preferred. You may report anonymously; if you would like credit for a confirmed finding, tell us how you would like to be named.

What you can expect from us

We will handle your report confidentially and will not share your identity with third parties without your permission, unless we are required to do so by law.

What we ask of you

Scope

The following are in scope:

The following are out of scope:

Good-faith research

We consider security research conducted in accordance with this policy to be authorized, and we welcome it. We do not intend to pursue legal action against researchers who follow this policy, report in good faith, and work with us to resolve what they find.

This policy does not authorize you to act in any way that is inconsistent with applicable law, and it does not limit the rights of any third party. If you are unsure whether a specific test is consistent with this policy, contact us at security@myonedose.com before proceeding and we will tell you.

Rewards

OneDose does not currently operate a paid bug bounty program, and we do not offer monetary rewards for reports. We do provide public credit for confirmed findings when you would like it.

Machine-readable policy

This policy is referenced from our security.txt file, published in accordance with RFC 9116.