Skip to main content

Security & Vulnerability Reporting

Updated this week

Reporting an Issue (Accidental Discovery)

If you are a user, patient, or provider and believe you have discovered a security issue, privacy leak, or vulnerability by accident:

  • Do not exploit it

  • Do not access or save any patient data

  • Report it immediately to infosec@doxy.me

We appreciate your report and will investigate immediately. Accidental good-faith reporting is protected under our Safe Harbor principles.

Active Security Research (Bug Bounty Program)

Doxy.me operates a Private, Invitation-Only Bug Bounty Program.

  • Testing of Production Systems is Strictly Prohibited: Due to HIPAA regulations and the sensitive nature of telehealth, you may not test our live production environments.

  • Authorized Environment: Active security research is only permitted on our designated Staging Environment.

  • Requirements: To participate, you must apply for enrollment. Accepted researchers will be required to sign an agreement and will be issued authorized test credentials.

How to Apply: To request an invitation to the program, please email infosec@doxy.me.

Warning: Conducting active security testing (scanning, probing, or exploiting) against doxy.me.me production systems without prior written authorization and a signed agreement is a violation of our Terms of Service and is not protected by Safe Harbor.

Did this answer your question?