Security Vulnerability Disclosure Policy

VITALL Platform and Medly Service

Last updated: August 19, 2026

Ensuring the security and privacy of our users and their data is our top priority. We adhere to leading security and privacy guidelines to ensure that your data remains confidential and is only used for its intended purpose.

If you've found a security vulnerability, we want to hear from you. We take every report seriously and will respond quickly.

Safe Harbour

We will not take legal action against you if you discover and report a vulnerability in good faith, following this policy.

We won't pursue civil or criminal action under the Computer Fraud and Abuse Act (CFAA), the Criminal Code of Canada, or equivalent legislation against researchers who act within these guidelines.

Scope

In Scope:
  • Medly patient app
  • Practitioner dashboard
  • Medly APIs and backend
  • Authentication and access controls
  • Patient data handling
Out of Scope:
  • Social engineering our staff
  • Physical access attacks
  • Denial of service testing
  • AWS, Apple, or Google infrastructure
  • Live patient accounts
  • Spam or phishing

How to report

Email your report to: security@vitall.com

Please include which component is affected, a description of the vulnerability, steps to reproduce, and the potential impact. Version numbers and proof-of-concept code are helpful. If you've reported to CISA, CERT/CC, or another coordination body, let us know.