biotrackOS
HomeCustomersSoonPricingSoon
Sign inGet started →
Product
Product overviewProfessional workspacePersonal appAutomationsTrigger follow-ups and recommendations from data.Integrations & capabilitiesMarketplacePartners & programmes.IntelligenceAI-powered health intelligence.API & SDKSoon
Markets
ClinicsPrimary & community careHealth systemsSports teamsGymsCorporate wellnessInsuranceResearch & pharmaPublic healthPersonal
New
A 20-minute walkthrough.

See a real clinic cohort, your data sources, and live alerts.

Book a demo →
Learn
BlogCustomer storiesSoonResearchOne Health CollectiveSoonOur clinician advisory network.
Trust
Trust & securitySoonSecurity disclosure
Where Trust Meets Technology. Inside Our Partnership with TRAIN Health Awareness
Latest
Where Trust Meets Technology. Inside Our Partnership with TRAIN Health Awareness

Inside a community health day TRAIN ran at one of Amsterdam's largest mosques, and why it's a blueprint for the TRAIN app, powered by BiotrackOS.

Read article →
Company
About BiotrackOSCareersPressContactSales, support, partnerships.
Legal
TermsPrivacyCookiesData processing
  • Home→
  • Product
    • Product overview
    • Professional workspace
    • Personal app
    • AutomationsTrigger follow-ups and recommendations from data.
    • Integrations & capabilities
    • MarketplacePartners & programmes.
    • IntelligenceAI-powered health intelligence.
    • API & SDKSoon
    Markets
    • Clinics
    • Primary & community care
    • Health systems
    • Sports teams
    • Gyms
    • Corporate wellness
    • Insurance
    • Research & pharma
    • Public health
    • Personal
  • CustomersSoon
  • PricingSoon
  • Learn
    • Blog
    • Customer storiesSoon
    • Research
    • One Health CollectiveSoon
    Trust
    • Trust & securitySoon
    • Security disclosure
  • Company
    • About BiotrackOS
    • Careers
    • Press
    • ContactSales, support, partnerships.
    Legal
    • Terms
    • Privacy
    • Cookies
    • Data processing
Sign in
Trust

Vulnerability disclosure.

Vulnerability Disclosure PolicyVersion 2.1 · Last updated 5 August 2026

BiotrackOS Ltd (“BiotrackOS”, “we”, “our”), registered in Scotland (No. SC737158), operates a health-data platform and takes the security of our systems and the privacy of personal health data seriously. If you have found a vulnerability in any BiotrackOS product or service, this policy explains how to report it safely and what you can expect from us. This is a coordinated vulnerability disclosure policy, not a paid bug-bounty programme.

This policy covers vulnerability reporting only. For details of our operational security measures — encryption, access controls, penetration testing, and compliance — see our Trust & Security page.

How to report

In short

Email security@biotrackos.com with reproduction steps. Encrypt sensitive reports using our public PGP key. Do not include real personal or health data in your report.

Email security@biotrackos.com with:

  • A clear description of the vulnerability and affected system.
  • Step-by-step reproduction instructions.
  • Supporting evidence (screenshots, HTTP traces, proof-of-concept code) — using only synthetic or your own test data.
  • Your contact details and preferred method of follow-up.

A machine-readable security.txt is published at biotrackos.com/.well-known/security.txt in accordance with RFC 9116 and NCSC guidance.

Health and personal data

In short

If you encounter real personal or health data during testing, stop immediately, do not download or retain it, and tell us right away.

BiotrackOS processes personal health data. If during your research you encounter what appears to be real Member or User personal data (including health records, identifiers, or credentials):

  • Stop testing immediately on that system or data path.
  • Do not download, copy, or retain the data.
  • Redact all personal data from any supporting evidence before sending your report.
  • Notify us promptly at security@biotrackos.com so we can assess whether a reportable data breach has occurred.

Inadvertent exposure of real personal data does not automatically disqualify you from safe-harbour protection, provided you follow the steps above.

Scope

In short

Our own domains and apps are in scope. Third-party services are out of scope — but vulnerabilities caused by our configuration or integration of them are reportable.

In scope

  • biotrackos.com and all subdomains (marketing site, platform dashboard, APIs)
  • BiotrackOS iOS app (App Store)
  • BiotrackOS Android app (Google Play)
  • BiotrackOS APIs hosted on BiotrackOS infrastructure

Out of scope

  • Third-party services we use (Stripe, Mailgun, Sentry, Firebase, AWS) — report these directly to those vendors. Vulnerabilities arising from our misconfiguration or integration of a third-party service remain reportable to us.
  • Attempts to manipulate BiotrackOS staff into revealing credentials or granting access (social engineering) — these are not technical vulnerabilities in our systems.
  • Physical security of offices or data centres.
  • Denial-of-service or brute-force attacks at scale.
  • Reports about spam, impersonation on social media, or phishing emails you have received — these should be forwarded to security@biotrackos.com but are handled separately from vulnerability reports.

Testing restrictions

In short

Test only on accounts you own or have explicit permission to test. Do not exfiltrate data, disrupt the service, or upload real personal data into reports.

To remain within this policy and within safe-harbour protection, you must not:

  • Test using accounts or data belonging to other people without their explicit written consent.
  • Exfiltrate data beyond the minimum necessary to demonstrate the vulnerability; do not retain copies.
  • Perform lateral movement, privilege escalation, or persistent access beyond what is needed to confirm a finding.
  • Use credential-stuffing techniques or credentials obtained from third-party breaches.
  • Conduct destructive testing, deploy malware, or take any action likely to disrupt service availability or data integrity.
  • Upload real personal data or health data into bug-report attachments, proof-of-concept files, or any third-party system.
  • Run high-volume automated scanning without prior written approval from security@biotrackos.com.

What we aim to do

In short

We aim to acknowledge within 2 business days and provide triage within 5. We will keep you updated while we work the issue.

  • We aim to acknowledge receipt within 2 business days.
  • We aim to provide an initial triage assessment within 5 business days.
  • We will maintain regular communication with you while we investigate and remediate.
  • We ask for a 90-day coordinated disclosure window before public disclosure; we will work with you if a different timeline is needed.

Rewards and credit

In short

This is not a paid bug-bounty programme. We do not normally pay for reports. We are happy to credit researchers publicly with their consent.

This is a coordinated vulnerability disclosure policy, not a paid bug-bounty programme. Reports are not normally eligible for financial reward. We are grateful for responsible security research and, with your consent, are happy to publicly acknowledge your contribution — for example on our Trust & Security page or in a release note. Credit is entirely at your discretion.

Safe harbour

In short

Research conducted in good faith under this policy is authorised. We will not take legal action against you for that research.

Research conducted in good faith and in accordance with this policy is authorised by BiotrackOS for systems we own or control. We will not initiate legal action or refer that research to law enforcement. If a third party initiates legal action arising from research that complied with this policy, we may confirm that the research was conducted in accordance with it. This authorisation does not extend to third-party systems or to conduct that BiotrackOS has no legal authority to permit.

Contact

Vulnerability reports and security enquiries: security@biotrackos.com
BiotrackOS Ltd (SC737158) · Canniesburn Gate, 10 Canniesburn Drive, Bearsden, Glasgow, Scotland, G61 1BF

The operating system
for connected health.

Every signal the body generates. One record. Always up to date.

Book a demo →How it works
biotrackOS

Built for the people behind the data.

Product
  • Product overview
  • PricingSoon
  • Professional workspace
  • Personal app
  • Automations
  • Integrations & capabilities
  • Marketplace
  • Intelligence
  • API & SDKSoon
Markets
  • Clinics
  • Primary & community care
  • Health systems
  • Sports teams
  • Gyms
  • Corporate wellness
  • Insurance
  • Research & pharma
  • Public health
  • Personal
Company
  • About BiotrackOS
  • Careers
  • Press
  • Contact
Resources
  • Blog
  • Customer storiesSoon
  • Research
  • One Health CollectiveSoon
  • Trust & securitySoon
  • Status
© 2026 BiotrackOS
TermsPrivacyCookiesAccessibility