Reporting an Issue (Accidental Discovery)
If you are a user, patient, or provider and believe you have discovered a security issue, privacy leak, or vulnerability by accident:
Do not exploit it
Do not access or save any patient data
Report it immediately to infosec@doxy.me
We appreciate your report and will investigate immediately. Accidental good-faith reporting is protected under our Safe Harbor principles.
Active Security Research (Bug Bounty Program)
Doxy.me operates a Private, Invitation-Only Bug Bounty Program.
Testing of Production Systems is Strictly Prohibited: Due to HIPAA regulations and the sensitive nature of telehealth, you may not test our live production environments.
Authorized Environment: Active security research is only permitted on our designated Staging Environment.
Requirements: To participate, you must apply for enrollment. Accepted researchers will be required to sign an agreement and will be issued authorized test credentials.
How to Apply: To request an invitation to the program, please email infosec@doxy.me.
Warning: Conducting active security testing (scanning, probing, or exploiting) against doxy.me.me production systems without prior written authorization and a signed agreement is a violation of our Terms of Service and is not protected by Safe Harbor.
