Vulnerability disclosure.
BiotrackOS Ltd (“BiotrackOS”, “we”, “our”), registered in Scotland (No. SC737158), operates a health-data platform and takes the security of our systems and the privacy of personal health data seriously. If you have found a vulnerability in any BiotrackOS product or service, this policy explains how to report it safely and what you can expect from us. This is a coordinated vulnerability disclosure policy, not a paid bug-bounty programme.
How to report
Email security@biotrackos.com with reproduction steps. Encrypt sensitive reports using our public PGP key. Do not include real personal or health data in your report.
Email security@biotrackos.com with:
- A clear description of the vulnerability and affected system.
- Step-by-step reproduction instructions.
- Supporting evidence (screenshots, HTTP traces, proof-of-concept code) — using only synthetic or your own test data.
- Your contact details and preferred method of follow-up.
A machine-readable security.txt is published at biotrackos.com/.well-known/security.txt in accordance with RFC 9116 and NCSC guidance.
Health and personal data
If you encounter real personal or health data during testing, stop immediately, do not download or retain it, and tell us right away.
BiotrackOS processes personal health data. If during your research you encounter what appears to be real Member or User personal data (including health records, identifiers, or credentials):
- Stop testing immediately on that system or data path.
- Do not download, copy, or retain the data.
- Redact all personal data from any supporting evidence before sending your report.
- Notify us promptly at security@biotrackos.com so we can assess whether a reportable data breach has occurred.
Inadvertent exposure of real personal data does not automatically disqualify you from safe-harbour protection, provided you follow the steps above.
Scope
Our own domains and apps are in scope. Third-party services are out of scope — but vulnerabilities caused by our configuration or integration of them are reportable.
In scope
biotrackos.comand all subdomains (marketing site, platform dashboard, APIs)- BiotrackOS iOS app (App Store)
- BiotrackOS Android app (Google Play)
- BiotrackOS APIs hosted on BiotrackOS infrastructure
Out of scope
- Third-party services we use (Stripe, Mailgun, Sentry, Firebase, AWS) — report these directly to those vendors. Vulnerabilities arising from our misconfiguration or integration of a third-party service remain reportable to us.
- Attempts to manipulate BiotrackOS staff into revealing credentials or granting access (social engineering) — these are not technical vulnerabilities in our systems.
- Physical security of offices or data centres.
- Denial-of-service or brute-force attacks at scale.
- Reports about spam, impersonation on social media, or phishing emails you have received — these should be forwarded to security@biotrackos.com but are handled separately from vulnerability reports.
Testing restrictions
Test only on accounts you own or have explicit permission to test. Do not exfiltrate data, disrupt the service, or upload real personal data into reports.
To remain within this policy and within safe-harbour protection, you must not:
- Test using accounts or data belonging to other people without their explicit written consent.
- Exfiltrate data beyond the minimum necessary to demonstrate the vulnerability; do not retain copies.
- Perform lateral movement, privilege escalation, or persistent access beyond what is needed to confirm a finding.
- Use credential-stuffing techniques or credentials obtained from third-party breaches.
- Conduct destructive testing, deploy malware, or take any action likely to disrupt service availability or data integrity.
- Upload real personal data or health data into bug-report attachments, proof-of-concept files, or any third-party system.
- Run high-volume automated scanning without prior written approval from security@biotrackos.com.
What we aim to do
We aim to acknowledge within 2 business days and provide triage within 5. We will keep you updated while we work the issue.
- We aim to acknowledge receipt within 2 business days.
- We aim to provide an initial triage assessment within 5 business days.
- We will maintain regular communication with you while we investigate and remediate.
- We ask for a 90-day coordinated disclosure window before public disclosure; we will work with you if a different timeline is needed.
Rewards and credit
This is not a paid bug-bounty programme. We do not normally pay for reports. We are happy to credit researchers publicly with their consent.
This is a coordinated vulnerability disclosure policy, not a paid bug-bounty programme. Reports are not normally eligible for financial reward. We are grateful for responsible security research and, with your consent, are happy to publicly acknowledge your contribution — for example on our Trust & Security page or in a release note. Credit is entirely at your discretion.
Safe harbour
Research conducted in good faith under this policy is authorised. We will not take legal action against you for that research.
Research conducted in good faith and in accordance with this policy is authorised by BiotrackOS for systems we own or control. We will not initiate legal action or refer that research to law enforcement. If a third party initiates legal action arising from research that complied with this policy, we may confirm that the research was conducted in accordance with it. This authorisation does not extend to third-party systems or to conduct that BiotrackOS has no legal authority to permit.
Contact
Vulnerability reports and security enquiries: security@biotrackos.com
BiotrackOS Ltd (SC737158) · Canniesburn Gate, 10 Canniesburn Drive, Bearsden, Glasgow, Scotland, G61 1BF
