Security Disclosure Policy
How to report a vulnerability, what is in scope, and the safe-harbour promise for good-faith research.
Security disclosure policy
We welcome good-faith security research into SideClick. This policy says how to report a vulnerability, what is in scope, the rules that keep patients safe while you test, and what you can expect from us. Research that follows it is not a breach of the Acceptable Use Policy.
1. How to report
Email security@sideclick.io with enough detail to reproduce the issue: the product and version, the steps, and the impact you believe it has. We acknowledge reports within two business days and keep you informed as we investigate. Please do not send us patient data, even if you believe you have found a way to reach it; describe the path instead.
2. In scope
- The installed desktop applications (Windows, macOS) and the iPhone companion app.
- The clinician web app and the patient portal.
- The sync relay, the licensing service, and the Cloud edition's services and identity service.
- The storefront at sideclick.io and the update channel.
3. Out of scope
- Social engineering, physical attacks, and denial-of-service or volumetric testing.
- Spam, rate-limit-only findings, and automated-scanner output without a working proof of concept.
- The infrastructure of our hosting and delivery providers themselves (Amazon Web Services, Apple), which run their own programmes.
- The zero-knowledge design's inability to decrypt practice data, and the corresponding inability to recover data whose keys are lost: both are deliberate.
4. Rules
- Test only against your own installation, your own test practice, or a staging target we designate — never against a real practice or real patient data.
- Stop and report as soon as you can demonstrate an issue; do not go further to prove impact.
- Do not access, modify, or retain data that is not yours. If you encounter someone else's data by accident, stop, do not save it, and tell us.
- Give us a reasonable time to fix the issue before any public disclosure: 90 days from your report, or another period we agree together.
5. What you can expect
- We will not pursue legal action against researchers who act in good faith within this policy, and we will not report them to law enforcement for their research.
- We will work with you on a fix, tell you when it ships, and credit you if you wish.
- A paid bounty programme is not yet live. When one opens, its rules and reward schedule will be published here first.
SideClick (Pty) Ltd · security@sideclick.io Version 1.1 · Published 2026-09-12