Vulnerability Reporting
We welcome reports from security researchers and customer security teams. Please report privately and give us a reasonable opportunity to remediate before any public disclosure.
How to report
- Email info@itechlab.app with the subject line 'Security vulnerability report'
- Include the affected URL or module, reproduction steps and the impact you observed
- Include the date and time of testing so we can correlate our logs
Please do not
- Access, modify or exfiltrate real patient data
- Run denial-of-service or high-volume automated testing against production
- Use social engineering against staff or customers
- Disclose the issue publicly before remediation has been agreed
What happens next
- We acknowledge receipt and open an internal incident record
- We assess severity and confirm reproduction
- We remediate and, where a customer deployment is affected, notify the affected organisation
- We confirm closure with the reporter
Customer dependencies
- A published response-time commitment and any recognition or reward policy require management approval.
- A dedicated security@ mailbox and PGP key would strengthen this process and require configuration.
MedFlow home — Contact Ubora One Limited