Vulnerability Disclosure Policy
Domilia welcomes and encourages security researchers who report, in good faith, vulnerabilities in our systems. This page describes how to make a responsible report and what you can expect from us.
How to report
Send your report to our security team:
Include: a description of the vulnerability, reproduction steps, potential impact, and your contact details for follow-up.
Good-faith commitment (safe harbor)
We will not pursue legal action against researchers who follow this policy, act in good faith, avoid any harm to privacy and service availability, and allow us a reasonable time to remediate before any public disclosure.
Scope
In scope: Domilia applications and services (associated *.domilia.ca and *.azurestaticapps.net domains) and the API.
Out of scope: denial of service (DoS/DDoS), social engineering, staff phishing, physical access, and testing on accounts/data that are not yours.
Rules
- Access only the data strictly necessary to demonstrate the issue; do not store, disclose or destroy any data.
- No impact on service availability or integrity (no DoS, no tampering).
- Respect privacy: no patient/beneficiary data (PHI) may be viewed or exfiltrated.
- Coordinated disclosure: give us a reasonable time (90 days) before any publication.
Our commitment
- Acknowledgement within 5 business days.
- Assessment and prioritization per our vulnerability-management procedure.
- Updates on the fix and thanks (public credit if you wish).
Recognition
Domilia does not offer a monetary reward at this time (no paid bug bounty program). We publicly recognize responsible contributions (with your consent). A paid program may be introduced later.
Machine-readable policy: /.well-known/security.txt (RFC 9116).