Vulnerability Disclosure Policy
OneDose builds clinical decision support used by EMS providers in the field. We take the security of our platform seriously, and we welcome reports from security researchers who help us protect our customers and their patients. This policy explains how to report a vulnerability to us, what we ask of you, and what you can expect from us in return.
How to report
Send vulnerability reports to security@myonedose.com.
To help us assess and reproduce the issue quickly, please include:
- The product, domain, or endpoint affected
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept code, requests, or screenshots
- Any accounts, IP addresses, or timestamps you used during testing, so we can distinguish your activity from real attacks
Reports in English are preferred. You may report anonymously; if you would like credit for a confirmed finding, tell us how you would like to be named.
What you can expect from us
- We aim to acknowledge your report within 5 business days.
- We aim to provide an initial assessment within 10 business days, including whether we have been able to reproduce the issue and how we have prioritized it.
- We aim to provide progress updates at least every 30 days until the report is resolved or closed.
- We will let you know when the issue is resolved, and credit you for the finding if you have asked for it.
We will handle your report confidentially and will not share your identity with third parties without your permission, unless we are required to do so by law.
What we ask of you
- Give us a reasonable opportunity to investigate and remediate before disclosing your findings publicly or to any third party. We ask for 90 days from your initial report, and we are happy to coordinate timing with you.
- Make a good-faith effort to avoid privacy violations, degradation of service, and disruption to production systems.
- Use only your own accounts and test data. Do not interact with accounts, data, or devices belonging to others.
- Stop immediately if you encounter patient information or other protected health information. Do not access, copy, store, transmit, or further examine it. Tell us what you found and how you found it, and delete any copy in your possession. This is the single most important request in this policy.
- Do not use social engineering, phishing, or physical attacks against our staff, customers, or facilities.
Scope
The following are in scope:
myonedose.comand its subdomains- The OneDose mobile application for iOS and Android
- The OneStat administrative console
- The OneDose public API
The following are out of scope:
- Denial-of-service and volumetric or resource-exhaustion testing of any kind
- Social engineering, phishing, and physical security testing
- Findings that require physical access to a user’s unlocked device
- Third-party services and platforms we do not operate — please report those to the vendor directly
- Automated scanner output submitted without a demonstrated, exploitable impact
- Missing security headers, cookie flags, or TLS configuration preferences with no demonstrated exploit path
- Reports of outdated software versions with no demonstrated, exploitable vulnerability in our environment
Good-faith research
We consider security research conducted in accordance with this policy to be authorized, and we welcome it. We do not intend to pursue legal action against researchers who follow this policy, report in good faith, and work with us to resolve what they find.
This policy does not authorize you to act in any way that is inconsistent with applicable law, and it does not limit the rights of any third party. If you are unsure whether a specific test is consistent with this policy, contact us at security@myonedose.com before proceeding and we will tell you.
Rewards
OneDose does not currently operate a paid bug bounty program, and we do not offer monetary rewards for reports. We do provide public credit for confirmed findings when you would like it.
Machine-readable policy
This policy is referenced from our security.txt file, published in accordance with RFC 9116.