Report a vulnerability or privacy issue in PocketCaregiver.
We take the security and privacy of the health information in PocketCaregiver seriously. If you believe you have found a security vulnerability or a privacy issue, we want to hear from you.
Email support@pocketcaregiver.com with: a description of the issue and where you found it; steps to reproduce it or a proof of concept; and the potential impact, if you can assess it. We aim to acknowledge your report within 2 business days and to keep you updated as we investigate and resolve it.
If you make a good-faith effort to follow this policy, we will work with you to understand and resolve the issue promptly, we will not pursue or support legal action against you for your research, and we will recognize your contribution if you would like us to (you may stay anonymous).
Give us a reasonable opportunity to fix an issue before disclosing it publicly. Only interact with test accounts you own or have explicit permission to access. Stop and report immediately if you encounter any real patient or personal health information.
Access, modify, download, or store other people's data. Run attacks that degrade or disrupt the service (such as denial-of-service, spam, or automated high-volume scanning). Use social engineering, phishing, or physical attacks against our users, staff, or infrastructure. Publicly disclose a vulnerability before we have had a reasonable chance to address it.
In scope: the PocketCaregiver web application and its backend (authentication, access controls, data storage, edge functions, file storage). Out of scope: issues in third-party services we rely on (report those to the relevant provider), best-practice suggestions without a demonstrated security impact, and reports generated solely by automated scanners without a working proof of concept.
If your report concerns how we handle personal or health data rather than a technical vulnerability, you can also reach us through our Privacy Rights page and our Consumer Health Data Privacy Policy.