Vulnerability Disclosure
Last updated August 2026. If you have found a security problem in Attergo, we want to hear about it and we will not make that difficult.
One business day
Five business days
What to send
Enough for us to reproduce it: the affected endpoint or screen, the steps, and what you observed. A proof of concept helps. If you can tell us what an attacker could reach, say so plainly rather than softening it.
Do not include patient data in your report. If your finding involves protected health information, tell us that it does and describe the shape of the exposure. Do not paste the data itself, do not retain a copy, and do not send it to a third party. Say what you saw and we will reproduce it ourselves.
What we commit to
- Acknowledgement from a human within one business day.
- An initial assessment, including whether we agree it is a vulnerability and our severity rating, within five business days.
- Remediation of a confirmed critical issue within seven days, and a written explanation if that is not possible.
- An update at least every fourteen days until it is closed, whether or not there is progress. Silence is not an acceptable status.
- Credit in our disclosure record if you want it, and none if you do not.
Good-faith research
We will not pursue legal action against you for security research conducted in good faith under this policy, and we will not ask a third party to do so on our behalf. Good faith means: you made a genuine effort to avoid harm to patients, customers and the availability of the service; you stopped as soon as you confirmed the issue; you did not access, modify, exfiltrate or retain data beyond the minimum needed to demonstrate it; and you gave us a reasonable opportunity to fix it before disclosing publicly.
What is out of scope
- Denial of service, load testing and anything that degrades the service for a real pharmacy. There is no scenario in which this is good-faith research against a live healthcare system.
- Social engineering of our staff or our customers, and physical attacks on any premises.
- Reports produced by a scanner with no demonstrated impact, missing security headers with no exploit path, and issues in third-party services we do not control.
- Anything requiring access to a customer's account that you were not authorized to have. If you are a customer testing your own tenant, tell us first and we will agree a window.
We do not run a paid bounty
Stated plainly because you deserve to know before you spend your time. We will credit you, we will tell you what we fixed and when, and we will answer your questions about it. What we will not do is imply a reward and then decline to pay one.
If you are a customer and you think you have been breached
Contact security@attergo.com immediately and say so in the subject line. Our obligations to you in that situation, including notification timing, are set out in the business associate agreement and are not modified by this page.