Responsible Disclosure
Protecting sensitive healthcare information is central to Seald Healthcare’s mission. We welcome reports from security researchers and others who identify potential vulnerabilities in our products or systems.
If you believe you have found a security issue, please report it privately so we can investigate and address it.
Report a vulnerability
What to Report
Please report suspected vulnerabilities affecting Seald Healthcare products or systems, including issues involving authentication, authorization, encryption, key management, APIs, applications, or unintended exposure of sensitive information.
If you are unsure whether an issue belongs here, contact us at security@sealdhealthcare.com with a brief description.
How to Submit a Report
Send your report to security@sealdhealthcare.com. Please include:
- The affected product, URL, endpoint, or software version.
- A description of the issue and its potential security impact.
- Clear steps to reproduce the issue.
- A minimal proof of concept, screenshots, or logs, where appropriate.
- Any conditions or permissions needed to reproduce the behavior.
- Contact details if you would like us to follow up.
Provide only the information necessary to understand the issue. Redact personal information, credentials, access tokens, and other sensitive material.
Do not include patient records or protected health information in your report. If investigating the issue requires a sensitive exchange, contact us first to arrange an appropriate transfer method.
Scope & Testing Permission
We welcome reports about suspected vulnerabilities in Seald Healthcare products and systems. Accepting a report does not authorize testing of every system associated with Seald Healthcare.
Before conducting active testing against a live service, contact us to agree on the specific systems and permitted testing activities.
Do not test customer environments, third-party services, or accounts and data you do not own without explicit permission from the responsible owner. A connection to Seald Healthcare does not place those systems within an authorized testing scope.
You do not need prior approval to report an issue you have already encountered.
Research Guidelines
Protect the privacy of individuals and the availability of the systems you interact with.
- Use your own accounts and synthetic test data within an agreed testing scope.
- Limit testing to what is necessary to demonstrate the issue.
- Do not access, download, alter, or delete another person’s data.
- Do not perform denial-of-service attacks, disruptive scanning, brute-force attacks, spam, phishing, or other social engineering.
- Do not install malware, establish persistent access, or use a finding to move into other systems.
- Stop testing once you have enough information to report the issue.
If you unexpectedly encounter patient information, credentials, or other sensitive data, stop immediately and notify us. Do not investigate further, copy the data, or include it in your report.
Coordinating Disclosure
Please report findings privately and give us a reasonable opportunity to investigate and address the issue before publishing technical details.
We welcome a discussion about disclosure timing and will work with you to coordinate publication in a way that protects customers and supports useful security research.
What You Can Expect
When you provide a way to contact you, we will acknowledge your report and review the information provided.
We will assess the issue based on its potential impact, request additional details when needed, and communicate relevant progress and resolution information where possible.
The time required to investigate and address an issue depends on its severity, complexity, and any third-party dependencies.
Recognition & Rewards
We appreciate the time and expertise involved in responsible reporting. This policy does not promise payment or a financial reward.
Any public acknowledgment will be discussed with you in advance and made only with your consent.
Found a Potential Vulnerability?
Help us investigate it safely. Send a report to security@sealdhealthcare.com.
Report a Vulnerability