Ensuring the security and privacy of our users and their data is our top priority. We adhere to leading security and privacy guidelines to ensure that your data remains confidential and is only used for its intended purpose.
If you've found a security vulnerability, we want to hear from you. We take every report seriously and will respond quickly.
We will not take legal action against you if you discover and report a vulnerability in good faith, following this policy.
We won't pursue civil or criminal action under the Computer Fraud and Abuse Act (CFAA), the Criminal Code of Canada, or equivalent legislation against researchers who act within these guidelines.
Email your report to: security@vitall.com
Please include which component is affected, a description of the vulnerability, steps to reproduce, and the potential impact. Version numbers and proof-of-concept code are helpful. If you've reported to CISA, CERT/CC, or another coordination body, let us know.